ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsHard

A CISA is reviewing an organization's identity and access management (IAM) system. The organization uses a single sign-on (SSO) solution across multiple cloud services. Which of the following is the MOST critical risk when a single point of failure exists in the SSO infrastructure?

  1. AComplete loss of access to all integrated applications and services.
  2. BDifficulty in enforcing consistent password policies across services.
  3. CExposure of user credentials if the SSO provider experiences a data breach.
  4. DIncreased administrative overhead for managing user accounts.
Show answer & explanation

Correct answer: A. Complete loss of access to all integrated applications and services.

While all options represent valid concerns, the MOST critical risk of a single point of failure in an SSO infrastructure is the complete loss of access to all integrated applications and services. If the SSO system itself becomes unavailable, users cannot authenticate to any connected service, leading to a widespread denial of service and severe business disruption. Exposure of credentials is a critical security risk, but loss of access is the immediate and most impactful operational risk of a single point of failure.

Why the other options are wrong

  • B. SSO generally simplifies consistent password policy enforcement, not complicates it.
  • C. This is a risk of the SSO provider's security, but not directly a risk of a 'single point of failure' in the infrastructure itself which relates to availability.
  • D. SSO typically reduces administrative overhead, so this is not a risk of a single point of failure.

SSO Single Point of Failure

A vulnerability in a Single Sign-On (SSO) system where the failure of a single component or service within the SSO infrastructure leads to the unavailability of all applications and services that rely on it for authentication.

  • Impacts system availability.
  • Can cause widespread business disruption.
  • Mitigated by high availability and redundancy.

Memory trick: One key to all doors means if the key breaks, all doors are locked.

More Domain 5: Protection of Information Assets questions