ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is auditing the implementation of security controls in a new data center. The organization handles highly sensitive personal data. The CISA observes that physical access to the server racks is controlled by a badge reader, but the badge reader logs are only reviewed quarterly. Which of the following is the MOST significant risk associated with this finding?

  1. APotential for badge cloning or unauthorized badge sharing.
  2. BDifficulty in identifying unauthorized access attempts in a timely manner.
  3. CNon-compliance with internal policy for physical security controls.
  4. DIncreased operational costs due to delayed incident response.
Show answer & explanation

Correct answer: B. Difficulty in identifying unauthorized access attempts in a timely manner.

While all options represent potential concerns, the MOST significant risk of quarterly review of badge reader logs is the inability to identify and respond to unauthorized physical access attempts in a timely manner. This delay could allow an attacker prolonged access, leading to severe data breaches or system tampering before detection. Other risks are consequences or related issues, but delayed detection is the direct, primary impact on security.

Why the other options are wrong

  • A. Badge cloning/sharing is a potential vulnerability, but the delayed log review exacerbates the risk by allowing such activity to go unnoticed for extended periods.
  • C. Non-compliance is a finding, but the risk is the consequence of that non-compliance, which is delayed detection.
  • D. Increased operational costs are a business impact, not the primary security risk of delayed detection.

Physical Access Log Review

The systematic examination of records generated by physical access control systems (e.g., badge readers, turnstiles) to identify unauthorized entry attempts, policy violations, or suspicious activity.

  • Crucial for detecting physical security breaches.
  • Review frequency impacts detection timeliness.
  • Supports forensic investigation.

Memory trick: If you don't check the visitor log often, you won't know who's inside.

More Domain 5: Protection of Information Assets questions