ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITEasy

A CISA is evaluating an organization's human resources management practices related to IT. The CISA observes that new IT employees are granted broad system access immediately upon joining, with access reviews conducted only annually. What is the MOST significant risk associated with this practice?

  1. AElevated risk of unauthorized access and data breaches.
  2. BDifficulty in conducting effective IT audits.
  3. CReduced employee productivity due to access complexity.
  4. DIncreased cost due to unnecessary software licenses.
Show answer & explanation

Correct answer: A. Elevated risk of unauthorized access and data breaches.

Granting broad access immediately and conducting infrequent reviews creates a significant window of opportunity for unauthorized actions, whether accidental or malicious. This practice directly increases the risk of data breaches and compromises system integrity, as access is not aligned with the principle of least privilege or need-to-know.

Why the other options are wrong

  • B. Audits might be more complex, but the primary risk is the security vulnerability itself, not just the audit's ease.
  • C. Broad access typically reduces, not increases, complexity for the user, though it's bad for security.
  • D. While possible, increased license costs are a minor concern compared to security risks.

Least Privilege Principle

A security principle requiring that users and processes are granted only the minimum necessary authorizations to perform their functions, and no more.

  • Minimizes potential damage from errors or malicious acts.
  • Reduces attack surface.
  • Requires regular access reviews.

Memory trick: Too many keys too soon means open doors for trouble.

More Domain 2: Governance and Management of IT questions