An improperly established relationship between IT and users poses the risk that there may be inadequate user security procedures. The objective of the questionnaire is to define adequate control procedures and to determine whether those procedures are in place.