A department has reported that a security control is no longer effective. Which of the following is the information security manager ' s BEST course of action?
The best first step is to assess the control state to determine why it is ineffective and whether adjustments, replacements, or compensating controls are needed.
“Regularly assess the effectiveness of security controls to ensure they are providing the intended level of protection.”
— CISM Review Manual 15th Edition, Chapter 3: Information Security Program Development and Management, Section: Control Monitoring and Assessment*
ISACA practice questions stress that assessing the control state comes before taking further action.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit