ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsHard

A CISA is auditing an organization's privileged access management (PAM) system. The PAM solution requires administrators to request temporary access, which is then approved by a manager, and sessions are recorded. However, the CISA discovers that a critical set of 'break-glass' administrator accounts, designed for emergency use, are exempt from the request/approval workflow and have their activities logged only locally on the target systems, with logs not centralized. What is the MOST significant control weakness in this 'break-glass' account management?

  1. AInsufficient frequency of auditing break-glass account usage.
  2. BAbsence of centralized logging and monitoring for break-glass activities.
  3. CThe ability to bypass the request/approval process for emergency accounts.
  4. DLack of multi-factor authentication (MFA) for break-glass accounts.
Show answer & explanation

Correct answer: B. Absence of centralized logging and monitoring for break-glass activities.

While 'break-glass' accounts are designed to bypass standard workflows, robust logging and centralized monitoring are critical compensating controls. Without centralized logging, it becomes extremely difficult to detect misuse, reconstruct events, or perform effective forensic analysis if a break-glass account is compromised or abused, making it a significant control weakness.

Why the other options are wrong

  • A. Audit frequency is a management decision; the fundamental issue is the lack of centralized, tamper-resistant logs for the audit to even review effectively.
  • C. Bypassing request/approval is inherent to the 'break-glass' concept; the weakness is not having adequate compensating controls for this bypass.
  • D. MFA is important, but the question implies the issue is *after* authentication, during activity logging/monitoring.

Break-Glass Account Management

Emergency access accounts designed to bypass normal privileged access controls in critical situations, requiring strong compensating controls like centralized logging and strict oversight.

  • Bypasses standard workflows for speed in emergencies.
  • Requires robust compensating controls (e.g., centralized logging, alerts).
  • Usage must be thoroughly documented and reviewed post-event.

Memory trick: The emergency key lets you in, but the big eye is always watching and logging everything.

More Domain 5: Protection of Information Assets questions