ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITEasy
A CISA is reviewing an organization's human resources management practices. The CISA discovers that access permissions for employees who have transferred departments are often not updated for several weeks, allowing them to retain access to their previous department's sensitive data. Which of the following is the MOST significant risk exposed by this practice?
- AHigher cost associated with maintaining unnecessary licenses.
- BDifficulty in auditing historical access logs.
- CIncreased operational inefficiency due to managing redundant access.
- DViolation of the principle of least privilege.
Show answer & explanationAnswer & explanation
Correct answer: D. Violation of the principle of least privilege.
The principle of least privilege dictates that users should only have access to the resources absolutely necessary to perform their job functions. Retaining access to previous department's data after a transfer directly violates this principle, significantly increasing the risk of unauthorized access and data breaches.
Why the other options are wrong
- A. Cost is a concern, but the security risk of unauthorized data access is a more critical finding for a CISA.
- B. Auditing might be more complex, but the primary risk is the unauthorized access itself, not just the difficulty in tracking it.
- C. While possible, operational inefficiency is less significant than the security risk of unauthorized access.
Principle of Least Privilege
A security principle requiring that a user or process be granted only the minimum access rights necessary to perform its job function, and no more.
- Reduces the attack surface and potential damage from breaches.
- Applies to all types of access: data, systems, networks.
- Requires regular review and adjustment of permissions.
Memory trick: Least Privilege: Only use the smallest key for the lock.