nerdexam
Isaca

CISM · Question #169

Once a suite of security controls has been successfully implemented for an organization's business units, it is MOST important for the information security manager to:

The correct answer is A. ensure the controls are regularly tested for ongoing effectiveness.. Security is not a one-time achievement - threats evolve, systems change, and controls degrade over time. Regularly testing controls for ongoing effectiveness ensures they continue to work as intended and provide the protection they were designed to deliver. This aligns with conti

Submitted by helene.fr· Apr 18, 2026Information Security Program Development and Management

Question

Once a suite of security controls has been successfully implemented for an organization's business units, it is MOST important for the information security manager to:

Options

  • Aensure the controls are regularly tested for ongoing effectiveness.
  • Bhand over the controls to the relevant business owners.
  • Cprepare to adapt the controls for future system upgrades.
  • Dperform testing to compare control performance against industry levels.

How the community answered

(41 responses)
  • A
    83% (34)
  • B
    10% (4)
  • C
    5% (2)
  • D
    2% (1)

Explanation

Security is not a one-time achievement - threats evolve, systems change, and controls degrade over time. Regularly testing controls for ongoing effectiveness ensures they continue to work as intended and provide the protection they were designed to deliver. This aligns with continuous improvement principles in frameworks like ISO 27001 and NIST. Handing controls to business owners (B) without ongoing oversight creates accountability gaps. Preparing for future upgrades (C) is forward-looking planning, not operational assurance. Benchmarking against industry levels (D) is useful but secondary to confirming the controls actually function correctly in the current environment.

Topics

#Control testing#Control effectiveness#Security program management#Continuous monitoring

Community Discussion

No community discussion yet for this question.

Full CISM Practice