ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

An organization is implementing a new enterprise resource planning (ERP) system that will handle highly sensitive financial data. The CISA is tasked with evaluating the data encryption strategy for this system. The organization plans to use symmetric encryption for data at rest. Which of the following is the MOST critical control to ensure the long-term effectiveness and security of this encryption strategy?

  1. AEstablishing a comprehensive key management system (KMS) for secure generation, storage, and rotation of encryption keys.
  2. BImplementing a robust Intrusion Detection System (IDS) to monitor access to encrypted data files.
  3. CRegularly performing penetration tests on the ERP system to identify potential vulnerabilities.
  4. DEnsuring that the symmetric encryption algorithm used is compliant with FIPS 140-2 standards.
Show answer & explanation

Correct answer: A. Establishing a comprehensive key management system (KMS) for secure generation, storage, and rotation of encryption keys.

For symmetric encryption, the security of the encryption keys is paramount. A strong key management system (KMS) is critical for securely generating, storing, distributing, rotating, and revoking these keys. Without a robust KMS, even the strongest encryption algorithm can be rendered ineffective if the keys are compromised, making it the most critical control for long-term encryption effectiveness.

Why the other options are wrong

  • B. While IDS is important for monitoring, it does not directly secure the encryption keys, which is the core vulnerability in symmetric encryption.
  • C. Penetration tests are valuable for identifying vulnerabilities, but they are a reactive measure. A proactive, foundational control like a KMS is more critical for the inherent security of the encryption strategy.
  • D. Using a FIPS-compliant algorithm is a good practice, but the algorithm itself is only as strong as the keys it uses. A strong algorithm with weak key management is still vulnerable.

Key Management System (KMS)

A system for managing cryptographic keys throughout their lifecycle, including generation, storage, distribution, rotation, and revocation, essential for the security of encrypted data.

  • Crucial for both symmetric and asymmetric encryption schemes.
  • Protects against unauthorized access to keys, which would compromise encrypted data.
  • Poor key management is a common cause of encryption failures.

Memory trick: A good KMS is the 'KEY' to strong encryption.

More Domain 5: Protection of Information Assets questions