ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsEasy

A CISA is auditing an organization's privileged access management (PAM) system. The organization has implemented a 'break-glass' account for emergency access to critical systems when normal authentication mechanisms fail. The CISA observes that the password for this account is stored in a shared, unencrypted document accessible by several IT administrators. What is the MOST significant security risk in this scenario?

  1. ADifficulty in auditing the use of the break-glass account.
  2. BIncreased administrative burden to manage the account password.
  3. CNon-compliance with password complexity policies.
  4. DCompromise of the break-glass account, leading to unauthorized privileged access.
Show answer & explanation

Correct answer: D. Compromise of the break-glass account, leading to unauthorized privileged access.

A break-glass account provides highly privileged access. Storing its password in a shared, unencrypted, and easily accessible document makes it extremely vulnerable to compromise. If compromised, an attacker gains immediate, uncontrolled privileged access to critical systems, bypassing all other security controls.

Why the other options are wrong

  • A. Auditing is crucial, but the compromise itself is a more fundamental and immediate risk.
  • B. While there might be some burden, the security risk of compromise far outweighs the administrative burden.
  • C. Password complexity is a related issue, but the storage method (unencrypted, shared) poses a more direct and severe threat than complexity alone.

Break-Glass Account Security

Controls and practices designed to secure highly privileged 'break-glass' accounts, which are used for emergency access to critical systems when normal access methods are unavailable.

  • Passwords must be highly protected and securely stored.
  • Access should be strictly limited and logged.
  • Usage requires multi-factor authentication and immediate review.

Memory trick: Leaving your emergency key under the doormat defeats the whole purpose of having a secure lock.

More Domain 5: Protection of Information Assets questions