ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingHard
A security auditor is reviewing an organization's cloud infrastructure. They discover that a critical S3 bucket, intended to store internal backups, is misconfigured, allowing public read access. This misconfiguration directly violates the organization's data classification policy which mandates strict confidentiality for backup data. Which type of audit finding does this primarily represent?
- APolicy non-compliance
- BOperational process failure
- CAdministrative control weakness
- DTechnical vulnerability
Show answer & explanationAnswer & explanation
Correct answer: A. Policy non-compliance
While the misconfiguration is a technical vulnerability, the core audit finding is that this technical state 'directly violates the organization's data classification policy'. An audit primarily checks adherence to policies and standards. Therefore, the most precise classification for this finding in an audit context is 'policy non-compliance'.
Why the other options are wrong
- B. An operational process failure could lead to this, but the audit identifies the 'violation of policy' as the immediate finding.
- C. While the administrative control (policy) exists, the failure is in adherence to it, making 'policy non-compliance' more accurate than a 'weakness' in the policy itself.
- D. It is a technical vulnerability, but the audit finding highlights the policy violation as the root issue from a governance perspective.
Audit Finding Categories
Classifications used in security audits to describe identified issues, often relating to policy adherence, control effectiveness, or technical vulnerabilities.
- Policy non-compliance: failure to follow rules
- Control weakness: a control is insufficient or ineffective
- Technical vulnerability: a specific flaw in a system
Memory trick: Audit: Policy breaks, weak controls, or tech flaws.