When Is an Information Security Control No Longer Relevant?

Answer Correct answer: B — Evaluate whether the control directly supports a specific business function before determining its operational relevance.

Which of the following is the BEST indication that an information security control is no longer relevant?

  1. The control is not cost efficient.
  2. The control does not support a specific business function. Correct Answer
  3. IT management does not support the control.
  4. The technology related to the control is obsolete.

Community Votes

B
83%
D
17%

83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests alignment between security controls and business objectives, while trapping candidates who confuse technological obsolescence with functional irrelevance.

This CISM question explores how to determine when a security control loses its business value, with community consensus confirming that misalignment with business functions is the definitive indicator of irrelevance.

Option D is frequently chosen because outdated technology seems outdated, but CISM emphasizes that a control remains relevant as long as it addresses a current business requirement, regardless of the underlying tech.

Community Discussion (6 comments)

hargit 👍 1 Selected: B
Not D: technology could stil be used (e.g. old PC in control room etc)
MMK777 👍 1 Selected: D
No longer relevant, which means it was relevant before
1899f17 👍 1
B. The control does not support a specific business function.
helg420 👍 1 Selected: B
also agree with B. Not all controls are related to technology
Der_Phomas 👍 1
Agree with B.
bronay 👍 3 Selected: B
B. The control doesn't support Business functions

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In CISM, security controls exist solely to mitigate risks that impact business objectives. When a control no longer supports a specific business function, it has lost its strategic purpose and becomes redundant. ISACA’s framework explicitly states that control effectiveness and relevance must be continuously evaluated against evolving business processes, making option B the definitive indicator.

Why the Other Options Are Wrong

Option A addresses financial optimization rather than operational relevance; a costly control may still be critical for compliance or risk avoidance. Option C reflects an organizational governance gap, not a technical or functional flaw in the control itself. Option D focuses on the underlying infrastructure, but legacy technology can still enforce valid security policies until properly replaced.

Community Comment Notes

Candidates like [1] and [4] correctly highlight that business function alignment is the core CISM principle. Comment [2] effectively counters the distractor by noting that older technology can still serve valid security purposes. Comment [5] reinforces that not all controls are technology-dependent, further validating why business alignment outweighs technical factors.

Official Reference

Exam Strategy

Always evaluate CISM questions through a business-risk lens first. Before selecting a technical or financial option, ask whether the scenario directly impacts business objectives or compliance requirements.

Frequently Asked Questions

Why isn't obsolete technology the best sign of irrelevance?

Outdated hardware or software can still enforce valid security policies until replaced. CISM prioritizes functional alignment over technological currency.

How do I know if a control is merely inefficient vs truly irrelevant?

Inefficiency suggests optimization or cost-benefit review, while irrelevance means the control no longer mitigates an active business risk.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide