ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceMedium
During an audit of an organization's incident management process, the IS auditor discovers that critical security incidents are frequently resolved without formal documentation of the root cause analysis. What is the MOST significant risk associated with this practice?
- ADifficulty in meeting service level agreement (SLA) recovery targets.
- BIncreased burden on incident response teams due to repetitive issues.
- CLack of clear communication with affected stakeholders during incidents.
- DInability to identify and address underlying systemic vulnerabilities.
Show answer & explanationAnswer & explanation
Correct answer: D. Inability to identify and address underlying systemic vulnerabilities.
Without formal documentation of root cause analysis, an organization cannot effectively identify and address the underlying systemic vulnerabilities that led to the incident, making it prone to recurrence.
Why the other options are wrong
- A. SLAs primarily focus on recovery time objectives (RTO) and recovery point objectives (RPO), not directly on the documentation of root cause analysis.
- B. While repetitive issues can increase burden, the inability to address root causes is a more fundamental and significant risk.
- C. Communication is important, but the lack of root cause analysis documentation doesn't directly prevent stakeholder communication; it hinders long-term problem resolution.
Root Cause Analysis (RCA)
A systematic process for identifying the underlying causes of problems or incidents, rather than just addressing their symptoms.
- Aims to prevent recurrence of issues.
- Involves detailed investigation and documentation.
- Crucial for continuous improvement in incident management.
Memory trick: Root causes are like bad roots, dig them out to grow better.