ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceMedium
An IS auditor is reviewing an organization's data management practices. The organization stores sensitive customer data across multiple cloud providers and on-premise systems. The auditor finds that while data classification exists, there is no centralized inventory detailing where specific types of sensitive data reside. What is the MOST significant risk posed by this lack of a centralized data inventory?
- AChallenges in implementing data encryption uniformly across all systems.
- BDifficulty in responding to data subject access requests (DSARs) and regulatory audits.
- CIncreased storage costs due to redundant data copies.
- DInefficient data backup and recovery processes.
Show answer & explanationAnswer & explanation
Correct answer: B. Difficulty in responding to data subject access requests (DSARs) and regulatory audits.
Without a centralized inventory of where sensitive data resides, an organization will struggle to accurately and completely respond to requests from data subjects (e.g., GDPR, CCPA) or demonstrate compliance to regulators. This can lead to significant fines and reputational damage, making it the most significant risk.
Why the other options are wrong
- A. While a challenge, encryption can often be managed per system. The inability to *find* the data is a more fundamental problem for compliance than uniform encryption application.
- C. While possible, increased storage costs are generally a less severe risk than regulatory non-compliance and legal penalties.
- D. Inefficient backup/recovery is a risk, but the ability to locate specific data for legal/regulatory purposes is often more critical for sensitive data.
Data Location Inventory Risk
The hazard of not knowing where specific types of sensitive data are stored across an organization's diverse IT landscape, leading to compliance failures and operational inefficiencies.
- Crucial for data privacy compliance (e.g., GDPR, CCPA).
- Supports effective data governance and security.
- Absence can lead to fines and reputational damage.
Memory trick: If you don't know where your treasures are, you can't protect them or show them off.