ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium
During a review of an organization's human resources management, the CISA notes that background checks for new IT employees are conducted only after they have been granted access to production systems. What is the MOST significant risk introduced by this practice?
- APotential for unauthorized access or malicious activity from unsuitable employees.
- BDelay in onboarding new IT personnel due to background check processing times.
- CDifficulty in integrating new employees into the IT team culture.
- DIncreased administrative burden on the HR department.
Show answer & explanationAnswer & explanation
Correct answer: A. Potential for unauthorized access or malicious activity from unsuitable employees.
Granting access to production systems before completing a background check exposes the organization to significant risk. An individual with a problematic background could potentially exploit this access for malicious purposes or inadvertently cause harm, making the organization vulnerable to security breaches and data compromise.
Why the other options are wrong
- B. While background checks can cause delays, this is not the most significant security risk of granting access prematurely.
- C. Cultural integration is an HR challenge, not the direct security consequence of premature system access.
- D. Administrative burden is an operational inefficiency, not the primary security risk of this practice.
Pre-Employment Screening
Pre-employment screening, including background checks, should be completed and reviewed before granting new employees access to sensitive systems or information to mitigate security and integrity risks.
- A preventive control to mitigate insider threats.
- Should precede access to critical resources.
- Verifies suitability and trustworthiness of candidates.
Memory trick: Don't hand out the keys before checking the driver's license.