CISM · Question #169
Once a suite of security controls has been successfully implemented for an organization's business units, it is MOST important for the information security manager to:
The correct answer is A. ensure the controls are regularly tested for ongoing effectiveness.. Security is not a one-time achievement - threats evolve, systems change, and controls degrade over time. Regularly testing controls for ongoing effectiveness ensures they continue to work as intended and provide the protection they were designed to deliver. This aligns with conti
Question
Once a suite of security controls has been successfully implemented for an organization's business units, it is MOST important for the information security manager to:
Options
- Aensure the controls are regularly tested for ongoing effectiveness.
- Bhand over the controls to the relevant business owners.
- Cprepare to adapt the controls for future system upgrades.
- Dperform testing to compare control performance against industry levels.
How the community answered
(41 responses)- A83% (34)
- B10% (4)
- C5% (2)
- D2% (1)
Explanation
Security is not a one-time achievement - threats evolve, systems change, and controls degrade over time. Regularly testing controls for ongoing effectiveness ensures they continue to work as intended and provide the protection they were designed to deliver. This aligns with continuous improvement principles in frameworks like ISO 27001 and NIST. Handing controls to business owners (B) without ongoing oversight creates accountability gaps. Preparing for future upgrades (C) is forward-looking planning, not operational assurance. Benchmarking against industry levels (D) is useful but secondary to confirming the controls actually function correctly in the current environment.
Topics
Community Discussion
No community discussion yet for this question.