ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceHard

An IS auditor is reviewing an organization's data management practices related to data archiving. The auditor notes that old, non-essential data is regularly moved from active production databases to an archive system. However, there is no documented process for periodic testing of the archived data's recoverability or integrity. What is the MOST significant risk this poses to the organization?

  1. AInability to retrieve or use archived data when legally or operationally required.
  2. BSlower access times for active production data due to archive system interaction.
  3. CNon-compliance with data retention policies if data is prematurely deleted.
  4. DIncreased storage costs for potentially corrupt archived data.
Show answer & explanation

Correct answer: A. Inability to retrieve or use archived data when legally or operationally required.

Archived data is typically retained for legal, regulatory, or historical business reasons. If its recoverability and integrity are not periodically tested, the organization risks discovering that the data is unusable or inaccessible precisely when it's needed for an audit, legal discovery, or critical business analysis. This renders the entire archiving effort useless and carries significant legal and operational consequences.

Why the other options are wrong

  • B. Archiving usually improves active database performance by offloading old data, so this is unlikely to be a direct risk of *untested* archives.
  • C. The scenario states data is moved to archive, not prematurely deleted. The risk is about the *usability* of the archived data, not its retention duration.
  • D. While storing corrupt data wastes space, the inability to use it when needed is a much more critical and direct risk.

Archived Data Integrity Risk

The danger that data moved to an archive system may become corrupt, unreadable, or otherwise unusable over time, especially if its recoverability and integrity are not regularly verified.

  • Compromises legal and regulatory compliance.
  • Undermines historical business intelligence.
  • Regular testing is crucial for data assurance.

Memory trick: Storing old documents in a box in the attic, but never checking if they're still legible.

More Domain 4: Information Systems Operations and Business Resilience questions