ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsEasy

A CISA is evaluating an organization's data encryption strategy. The organization uses symmetric encryption for bulk data storage and asymmetric encryption for key exchange and digital signatures. The CISA discovers that a single, master encryption key for all stored data is backed up on an unencrypted network share. What is the MOST significant risk associated with this finding?

  1. AAsymmetric encryption is not being used for bulk data encryption.
  2. BCompromise of the master key would require re-encrypting all data.
  3. CThe master key could be used to decrypt all data if discovered.
  4. DKey rotation practices may be difficult to implement effectively.
Show answer & explanation

Correct answer: C. The master key could be used to decrypt all data if discovered.

If a single master encryption key, especially one used for symmetric encryption of bulk data, is compromised and discovered due to being stored unencrypted, all data encrypted with that key becomes immediately vulnerable to decryption. This represents a complete failure of confidentiality.

Why the other options are wrong

  • A. Using symmetric encryption for bulk data is an appropriate and efficient practice; this is not a risk.
  • B. While re-encryption would be necessary, the primary risk is immediate data compromise, not the operational burden of re-encryption.
  • D. Key rotation challenges are a secondary concern; the immediate and critical risk is the compromise of the current key.

Master Encryption Key Protection

The practice of securely managing and protecting the primary encryption key used to encrypt and decrypt large volumes of data or other encryption keys.

  • Compromise of a master key leads to total data compromise.
  • Master keys should be stored in highly secure, encrypted environments.
  • Key management systems (KMS) are crucial for master key protection.

Memory trick: One key to rule them all, one key to bind them, and in the darkness, compromise them.

More Domain 5: Protection of Information Assets questions