ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsEasy

A CISA is auditing the identity and access management (IAM) system of a large financial institution. The institution uses a role-based access control (RBAC) model. The CISA discovers that several employees who have changed departments still retain access permissions associated with their previous roles, in addition to their new roles. What is the MOST significant risk introduced by this situation?

  1. AIncreased administrative overhead for managing user accounts and permissions.
  2. BViolation of the principle of least privilege, leading to potential unauthorized access and data breaches.
  3. CDifficulty in auditing user activities due to a complex array of inherited permissions.
  4. DInefficiencies in user productivity due to conflicting access rights from multiple roles.
Show answer & explanation

Correct answer: B. Violation of the principle of least privilege, leading to potential unauthorized access and data breaches.

Employees retaining permissions from previous roles, in addition to their current ones, directly violates the principle of least privilege. This significantly increases the attack surface, as users have access to resources they no longer need, creating opportunities for unauthorized access, data exfiltration, or privilege escalation if their accounts are compromised. This is a fundamental security risk in IAM.

Why the other options are wrong

  • A. While administrative overhead might increase, it is a operational inefficiency, not the most significant security risk compared to unauthorized access.
  • C. Auditing can indeed become difficult, but the difficulty in auditing is a symptom or consequence, not the fundamental security risk of having excessive access in the first place.
  • D. Conflicting access rights can cause productivity issues, but this is an operational concern, not the primary security risk of over-provisioned access.

Principle of Least Privilege

A security principle requiring that users, programs, or processes be granted only the minimum necessary rights or permissions to perform their authorized functions.

  • Reduces the attack surface and potential damage from a compromised account.
  • Requires regular review and revocation of unnecessary permissions.
  • Often violated by 'privilege creep' where users accumulate permissions over time.

Memory trick: Grant 'LEAST' privilege, not 'MOST' problems.

More Domain 5: Protection of Information Assets questions