ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium
A CISA is auditing an organization's identity and access management (IAM) system. The organization uses a role-based access control (RBAC) model. The CISA observes that many users have been granted 'temporary' elevated privileges that have not been revoked for several months, and the process for reviewing these temporary privileges is ad hoc. What is the MOST significant risk introduced by this situation?
- AIncreased administrative overhead for managing user accounts.
- BDifficulty in integrating new applications with the existing IAM system.
- CSlower user onboarding and offboarding processes.
- DViolation of the principle of least privilege, increasing the attack surface.
Show answer & explanationAnswer & explanation
Correct answer: D. Violation of the principle of least privilege, increasing the attack surface.
Accumulation of unrevoked temporary elevated privileges directly violates the principle of least privilege. This means users have more access than necessary for their job functions, significantly increasing the potential blast radius if an account is compromised or misused.
Why the other options are wrong
- A. While there might be some administrative overhead, it's not the most significant security risk.
- B. The issue is with privilege management for existing users, not general system integration capabilities.
- C. This scenario primarily concerns existing users and their privilege creep, not the speed of onboarding/offboarding.
Principle of Least Privilege
A security concept where users are granted only the minimum necessary access rights to perform their job functions, and these rights are revoked when no longer needed.
- Reduces the attack surface.
- Limits potential damage from compromised accounts.
- Requires regular review of user privileges.
Memory trick: Too many keys unlock too many doors, making your house vulnerable.