The correct answer is C because control performance can only be evaluated effectively when the testing method is appropriate for the objective of the evaluation. Different testing purposes require different methods. For example, control design effectiveness may be assessed through documentation review and interviews, while operating effectiveness may require sampling, observation, technical testing, or log review. Senior management support is useful, but it is not the most important factor in determining whether the evaluation will produce valid results. Interviewing control owners may provide useful information, but it may not independently confirm control effectiveness. International standards may provide useful criteria, but testing scenarios must be relevant to the organization’s actual risks, systems, and control objectives. CISM emphasizes that security control monitoring and evaluation should be risk-based, objective, and aligned with the intended control purpose. Selecting the right testing method ensures results are meaningful, reliable, and useful for management decision-making.
[Reference: CISM Information Security Program Development and Management; control monitoring, measurement, testing, and assurance principles., , ]
Submit