ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITEasy

An organization's information security policy mandates that all critical data must be encrypted both in transit and at rest. During a review, the CISA discovers that while data in transit is consistently encrypted using strong protocols, a significant portion of critical data stored on internal file servers and databases is not encrypted at rest. What is the MOST immediate security risk to the organization?

  1. AReduced system performance due to encryption/decryption processes.
  2. BDifficulty in performing data recovery from encrypted backups.
  3. CIncreased bandwidth consumption due to encryption overhead.
  4. DUnauthorized access to sensitive data if storage systems are compromised.
Show answer & explanation

Correct answer: D. Unauthorized access to sensitive data if storage systems are compromised.

If critical data at rest is not encrypted, it remains vulnerable to unauthorized access or disclosure if the storage system itself (e.g., a file server, database, or stolen hard drive) is compromised. This directly violates the policy and poses an immediate and severe security risk to the confidentiality of the data.

Why the other options are wrong

  • A. Performance impact is a technical concern, not the primary security risk of unencrypted data.
  • B. Data recovery from encrypted backups can be complex, but this is a recovery concern, not the immediate security risk of unencrypted live data.
  • C. Bandwidth consumption is related to data in transit, not data at rest, and is not a security risk.

Data at Rest Encryption

Data at rest encryption protects data stored on persistent storage devices (e.g., hard drives, databases, cloud storage) from unauthorized access in case of physical theft, system compromise, or unauthorized access to the storage medium.

  • Protects data when not actively moving or being used.
  • A fundamental control for data confidentiality.
  • Essential for compliance with many data protection regulations.

Memory trick: Leaving your valuables in an unlocked safe; if someone gets in, they're gone.

More Domain 2: Governance and Management of IT questions