ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium
A CISA is evaluating an organization's data encryption strategy for data at rest. The organization stores highly sensitive customer data in a database and uses full disk encryption on the database servers. Which of the following is the MOST critical control gap to address regarding the protection of the encryption keys?
- ALack of regular rotation of encryption keys.
- BInsufficient length of the encryption keys used.
- CStorage of encryption keys on the same servers as the encrypted data.
- DAbsence of a dedicated key management system (KMS).
Show answer & explanationAnswer & explanation
Correct answer: C. Storage of encryption keys on the same servers as the encrypted data.
Storing encryption keys on the same server as the encrypted data defeats a significant purpose of encryption, as compromise of the server would expose both the data and the means to decrypt it. This creates a single point of failure and a critical vulnerability.
Why the other options are wrong
- A. Key rotation is important for long-term security but not as critical as separating the key from the data itself.
- B. Insufficient key length is a serious issue, but the scenario implies full disk encryption, which typically uses strong, standard key lengths. The co-location of keys and data is a more immediate and fundamental flaw.
- D. While a KMS is best practice, its absence isn't as critical as the immediate risk of co-located keys. A basic, secure separate storage method is more important than an advanced system if the keys are otherwise unprotected.
Key Separation Principle
The principle that encryption keys should be stored and managed separately from the data they encrypt to prevent unauthorized access to both the data and the means to decrypt it.
- Reduces the risk of data compromise if the data storage is breached.
- Often implemented using Hardware Security Modules (HSMs) or Key Management Systems (KMS).
- A fundamental security control for data at rest and in transit.
Memory trick: Keys and Locks: Always Keep Them Apart to Secure Your Vault.