ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is auditing an organization's endpoint security. The organization uses a variety of operating systems (Windows, macOS, Linux) and mobile devices (iOS, Android) across its environment. The CISA notes that the current antivirus solution only supports Windows and macOS, and there is no centralized management for mobile device security. What is the MOST immediate and significant risk this scenario presents?

  1. AInconsistent application of security policies across all endpoints.
  2. BIncreased operational overhead for IT staff.
  3. CHigher probability of advanced persistent threats (APTs) targeting unsupported systems.
  4. DDifficulty in conducting forensic investigations on unsupported devices.
Show answer & explanation

Correct answer: A. Inconsistent application of security policies across all endpoints.

Without a consistent security solution and centralized management across all endpoint types, the organization cannot ensure uniform application of its security policies, leaving significant gaps and increasing overall risk. While other options are risks, inconsistent policy application is the overarching issue.

Why the other options are wrong

  • B. Increased overhead is a consequence, but not the primary security risk itself.
  • C. While unsupported systems are more vulnerable to various threats, including APTs, the root cause described is the inability to apply and manage security consistently, which is a broader and more immediate risk than just APTs.
  • D. Forensic investigation difficulty is a concern post-incident, but the immediate risk is the increased likelihood of an incident due to inadequate preventative controls.

Endpoint Security Coverage

The extent to which security controls (e.g., antivirus, EDR, patch management) are consistently applied and managed across all diverse computing devices (endpoints) within an organization's environment.

  • Ensures uniform application of security policies.
  • Reduces the attack surface by protecting all entry points.
  • Critical for managing diverse OS and device types.

Memory trick: Diverse Devices, Disjointed Defense: A Recipe for Policy Peril.

More Domain 5: Protection of Information Assets questions