ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessHard

During a risk-based audit planning process, an IS auditor identifies that a critical legacy system, which processes sensitive customer data, has not been updated with security patches for over two years. This system also lacks a dedicated security architect. Based on this information, which of the following represents the HIGHEST inherent risk to the organization?

  1. ALoss of system availability due to hardware failure.
  2. BPotential for increased operational costs due to system instability.
  3. CNon-compliance with internal security policies and external data protection regulations.
  4. DDifficulty in attracting new customers due to a perception of outdated technology.
Show answer & explanation

Correct answer: C. Non-compliance with internal security policies and external data protection regulations.

A critical legacy system processing sensitive customer data, unpatched for two years, and lacking a security architect, presents a severe vulnerability. This directly exposes the organization to breaches, which would lead to non-compliance with data protection regulations (e.g., GDPR, CCPA) and internal policies, resulting in significant fines, legal action, and reputational damage. While other options are risks, non-compliance with regulations for sensitive data is the most immediate and severe inherent risk in this scenario.

Why the other options are wrong

  • A. Hardware failure is a general risk for any system; the specific details (unpatched, sensitive data, no security architect) point more strongly to security and compliance risks.
  • B. Increased operational costs are a possibility but a less direct and immediate inherent risk compared to regulatory non-compliance for sensitive data.
  • D. Perception of outdated technology is a business risk, but not the highest *inherent risk* stemming directly from the unpatched, critical system handling sensitive data.

Inherent Risk

The risk that exists in the absence of any controls, representing the raw exposure to potential loss or harm.

  • Exists before considering any mitigating controls.
  • Determined by the nature of the business, assets, and threats.
  • High inherent risk requires strong controls to reduce residual risk.

Memory trick: Inherent risk is the raw danger, before any safety nets.

More Domain 1: Information System Auditing Process questions