ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium

A CISA is reviewing an organization's human resources management practices related to IT. The CISA finds that all IT employees, regardless of their role, are granted administrative privileges on their workstations and several production servers for 'convenience'. What is the MOST significant risk introduced by this practice?

  1. AChallenges in implementing effective phishing awareness training.
  2. BHigher likelihood of accidental data deletion or system misconfiguration.
  3. CIncreased difficulty in managing software licenses.
  4. DSlower system performance due to unauthorized software installations.
Show answer & explanation

Correct answer: B. Higher likelihood of accidental data deletion or system misconfiguration.

Granting administrative privileges broadly and unnecessarily significantly increases the risk of users, even inadvertently, causing harm through accidental data deletion, system misconfiguration, or introducing malware. This directly violates the principle of least privilege.

Why the other options are wrong

  • A. Phishing awareness is important for all users, but administrative privileges don't inherently make training more challenging.
  • C. Software license management is a separate issue, not directly caused by administrative privileges.
  • D. While possible, the primary and most direct risk of widespread administrative privileges is not performance degradation but rather system integrity and data security compromises.

Principle of Least Privilege

A security principle that dictates that a user, program, or process should be given only the minimum set of permissions necessary to perform its job or function, and no more.

  • Reduces the attack surface.
  • Limits potential damage from compromises or errors.
  • Requires careful access control management.

Memory trick: Too many keys, too many risks.

More Domain 2: Governance and Management of IT questions