ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium
A CISA is auditing an organization's access control system. The organization uses a role-based access control (RBAC) model. The CISA observes that when an employee changes departments, their old roles are sometimes deactivated, but their new roles are not always immediately provisioned, leading to temporary access gaps. Conversely, in other instances, employees retain access from their old department while also gaining new access, leading to excessive privileges. Which of the following is the MOST effective control to address these issues?
- AConducting regular separation of duties (SoD) analysis.
- BEnforcing the principle of least privilege.
- CImplementing a periodic access review process.
- DAutomating the user provisioning and deprovisioning process.
Show answer & explanationAnswer & explanation
Correct answer: D. Automating the user provisioning and deprovisioning process.
Automating user provisioning and deprovisioning ensures that access rights are granted and revoked consistently and promptly based on changes in an employee's role or status. This directly addresses both the temporary access gaps and the excessive privileges described.
Why the other options are wrong
- A. SoD analysis focuses on preventing conflicting duties, not on the timely and accurate provisioning/deprovisioning of access during departmental changes.
- B. While important, enforcing least privilege is a design principle; automation is the operational control that ensures it's applied consistently during changes.
- C. Periodic reviews are reactive; automation is proactive in preventing these issues from occurring.
Automated Identity and Access Management (IAM)
The use of technology to automatically manage user identities and their access privileges across an organization's systems and applications.
- Ensures timely provisioning and deprovisioning of access.
- Reduces human error and administrative overhead.
- Enhances security by enforcing consistent access policies.
Memory trick: Automatic updates keep the access gates always perfectly aligned with the employee's role.