Which THREE factors should an ISSMP consider when selecting security controls for a new system?
Controls must be relevant to the threats the organization faces.
Why this answer
Selecting controls involves balancing business requirements, regulatory compliance, and the actual threat landscape to ensure a proportionate risk response.