ISACA Certified Information Systems Auditor (CISA) ExamDomain 2: Governance and Management of ITMedium
A CISA is reviewing an organization's human resources management processes related to IT. The CISA notes that while background checks are performed for all new hires, there is no formal process for reviewing or updating these checks for existing employees who are promoted to more sensitive IT roles (e.g., from help desk to system administrator). What is the MOST significant risk this practice introduces?
- AIncreased administrative burden due to manual background check processes.
- BChallenges in complying with general data protection regulations (GDPR) regarding employee data.
- CDifficulty in maintaining an accurate and up-to-date employee security profile.
- DPotential for insider threats from employees with undetected changes in risk profile.
Show answer & explanationAnswer & explanation
Correct answer: D. Potential for insider threats from employees with undetected changes in risk profile.
When an employee moves to a more sensitive IT role, their access and potential impact on organizational assets increase significantly. Without re-evaluating their background, the organization misses an opportunity to detect any changes in their risk profile that might make them a heightened insider threat, directly jeopardizing security.
Why the other options are wrong
- A. Administrative burden is an operational inefficiency, not the primary security risk of this practice.
- B. GDPR compliance primarily concerns data privacy, not the security risk associated with an employee's trustworthiness in a sensitive role.
- C. While true, the difficulty in maintaining profiles is a symptom; the underlying risk is the security exposure from that lack of updated information.
Continuous Personnel Vetting
The ongoing process of monitoring and re-evaluating the trustworthiness and risk profile of employees, especially those in sensitive positions, beyond initial background checks, and particularly when roles change.
- Risk profiles can change over time.
- Crucial for roles with elevated access/privileges.
- Reduces insider threat potential.
Memory trick: Trust is earned, and re-earned, with new roles.