ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceMedium

An IS auditor is evaluating the organization's data management practices. The auditor discovers that different departments maintain their own copies of customer data, and there is no centralized process for data entry or updates. This leads to inconsistencies in customer records across various systems. Which of the following data management principles is PRIMARILY being violated?

  1. AData availability.
  2. BData confidentiality.
  3. CData security.
  4. DData integrity.
Show answer & explanation

Correct answer: D. Data integrity.

Data integrity refers to the accuracy, consistency, and reliability of data over its entire lifecycle. When multiple, unmanaged copies of the same data exist and are updated independently, it inevitably leads to inconsistencies and inaccuracies, which is a direct violation of data integrity.

Why the other options are wrong

  • A. Data availability ensures data is accessible when needed. While inconsistencies can impact usability, the core problem is not access but accuracy.
  • B. Data confidentiality protects sensitive data from unauthorized disclosure, which is not the primary concern here.
  • C. Data security relates to protecting data from unauthorized access or modification, which is not the primary issue described.

Data Integrity

Data integrity refers to the accuracy, consistency, and reliability of data over its entire lifecycle. It ensures that data is maintained in its correct and complete form and is not altered or corrupted.

  • Crucial for data quality and trustworthiness.
  • Violated by inconsistencies, errors, or unauthorized changes.
  • Supported by validation rules, consistency checks, and master data management.

Memory trick: Data Quality: 'C'onfidentiality, 'I'ntegrity, 'A'vailability

More Domain 4: Information Systems Operations and Business Resilience questions