When Is an Information Security Control No Longer Relevant?
Which of the following is the BEST indication that an information security control is no longer relevant?
Community Votes
83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests alignment between security controls and business objectives, while trapping candidates who confuse technological obsolescence with functional irrelevance.
This CISM question explores how to determine when a security control loses its business value, with community consensus confirming that misalignment with business functions is the definitive indicator of irrelevance.
Option D is frequently chosen because outdated technology seems outdated, but CISM emphasizes that a control remains relevant as long as it addresses a current business requirement, regardless of the underlying tech.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In CISM, security controls exist solely to mitigate risks that impact business objectives. When a control no longer supports a specific business function, it has lost its strategic purpose and becomes redundant. ISACA’s framework explicitly states that control effectiveness and relevance must be continuously evaluated against evolving business processes, making option B the definitive indicator.Why the Other Options Are Wrong
Option A addresses financial optimization rather than operational relevance; a costly control may still be critical for compliance or risk avoidance. Option C reflects an organizational governance gap, not a technical or functional flaw in the control itself. Option D focuses on the underlying infrastructure, but legacy technology can still enforce valid security policies until properly replaced.Community Comment Notes
Candidates like [1] and [4] correctly highlight that business function alignment is the core CISM principle. Comment [2] effectively counters the distractor by noting that older technology can still serve valid security purposes. Comment [5] reinforces that not all controls are technology-dependent, further validating why business alignment outweighs technical factors.Official Reference
Exam Strategy
Always evaluate CISM questions through a business-risk lens first. Before selecting a technical or financial option, ask whether the scenario directly impacts business objectives or compliance requirements.
Frequently Asked Questions
Why isn't obsolete technology the best sign of irrelevance?
Outdated hardware or software can still enforce valid security policies until replaced. CISM prioritizes functional alignment over technological currency.
How do I know if a control is merely inefficient vs truly irrelevant?
Inefficiency suggests optimization or cost-benefit review, while irrelevance means the control no longer mitigates an active business risk.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →