ISACA Certified Information Systems Auditor (CISA) ExamDomain 3: Information Systems Acquisition, Development and ImplementationHard
An organization is migrating its core banking application to a new cloud platform. The IS auditor is reviewing the data migration strategy. Which of the following is the MOST critical control for ensuring data integrity during this migration?
- AConducting comprehensive performance testing of the application on the new cloud platform.
- BImplementing checksums or hashing for all data transferred and comparing them post-migration.
- CEstablishing a detailed rollback plan in case of migration failure.
- DEnsuring encryption of data both in transit and at rest within the cloud environment.
Show answer & explanationAnswer & explanation
Correct answer: B. Implementing checksums or hashing for all data transferred and comparing them post-migration.
Checksums or hashing provide a cryptographic assurance that data has not been altered or corrupted during transfer. While other options are important for overall migration success and security, ensuring data integrity specifically means verifying that the data arriving is identical to the data sent.
Why the other options are wrong
- A. Performance testing ensures the application works well, but not that the migrated data is accurate.
- C. A rollback plan is crucial for recovery but does not proactively ensure the integrity of the data that was migrated.
- D. Encryption protects confidentiality and security, but does not inherently guarantee that the data itself remained unchanged during the move.
Data Migration Integrity
The assurance that data remains accurate, complete, and unchanged during its transfer from one system or location to another.
- Crucial for reliable system operation.
- Prevents data corruption and loss.
- Often verified using checksums or hashing.
Memory trick: Migrate data, but check its DNA!