ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessHard
An IS auditor is reviewing an organization's internal procedures for managing third-party vendor access to sensitive systems. The auditor notes that the procedures require annual review of vendor access rights, but there is no documented process for *revoking* access immediately upon contract termination or project completion. What type of control weakness does this MOST directly represent?
- AWeakness in compensating controls.
- BIneffective preventative controls.
- CLack of detective controls.
- DAbsence of corrective controls.
Show answer & explanationAnswer & explanation
Correct answer: B. Ineffective preventative controls.
A preventative control aims to stop an undesirable event from occurring. The immediate revocation of access upon termination is a preventative control designed to prevent unauthorized access by former third parties. The absence of a documented process for this immediate revocation means this crucial preventative control is ineffective or non-existent, leaving a significant vulnerability.
Why the other options are wrong
- A. Compensating controls are alternative controls when primary ones are not feasible. The issue is a missing primary preventative control, not a deficiency in a compensating one.
- C. Detective controls identify incidents *after* they occur. This issue is about preventing unauthorized access, not detecting it after it happens.
- D. Corrective controls aim to fix issues *after* they are detected. The problem here is about preventing the issue in the first place.
Preventative Controls
Controls designed to stop an undesirable event from occurring, thereby preventing errors, omissions, or malicious acts.
- Applied before an event takes place.
- Examples: access controls, segregation of duties, encryption, firewalls.
- More cost-effective than detective or corrective controls in the long run.
Memory trick: Preventative stops, Detective finds, Corrective fixes.