ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsHard

A CISA is auditing an organization's privileged access management (PAM) system. The organization has implemented a solution that stores credentials in a secure vault and rotates them automatically. However, the CISA observes that 'break-glass' accounts (emergency access accounts) are not regularly audited or tested, and their access logs are not systematically reviewed. What is the MOST significant risk posed by this oversight?

  1. APotential for undetected misuse or compromise of critical administrative credentials.
  2. BInability to quickly restore normal operations after a system failure.
  3. CIncreased operational overhead for managing emergency access procedures.
  4. DNon-compliance with industry best practices for privileged account security.
Show answer & explanation

Correct answer: A. Potential for undetected misuse or compromise of critical administrative credentials.

Break-glass accounts are highly privileged and designed for emergency use. If these accounts are not regularly audited, tested, or their access logs systematically reviewed, any misuse or compromise of these accounts could go undetected for extended periods. This poses the most significant risk because an attacker gaining control of a break-glass account would have virtually unrestricted and potentially untraceable access to critical systems, leading to severe data breaches, system damage, or complete control over the environment.

Why the other options are wrong

  • B. This relates to the *availability* of the break-glass accounts. The risk highlighted is the potential *misuse* or *compromise* due to lack of audit/review, implying the accounts might function but be maliciously used.
  • C. Operational overhead is a management concern, not the most significant security risk of compromised super-privileged accounts.
  • D. Non-compliance is a serious issue, but it's a consequence of the underlying security vulnerability, which is the potential for undetected misuse of highly privileged accounts.

Break-Glass Account Security

The practice of securely managing, auditing, and monitoring emergency access (break-glass) accounts, which grant highly privileged access to critical systems.

  • Designed for use only in emergencies when normal PAM processes fail.
  • Requires stringent controls: strong authentication, strict access criteria, robust logging.
  • Mandates regular auditing, review of usage logs, and periodic testing of functionality.
  • Compromise of these accounts poses extreme risk.

Memory trick: Don't leave the 'EMERGENCY KEY' unchecked; it's a 'TREASURE' for thieves.

More Domain 5: Protection of Information Assets questions