ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceEasy
An IS auditor is evaluating the effectiveness of an organization's information systems operations. The auditor observes that system logs are collected and stored but are not regularly reviewed or analyzed for anomalies. What is the MOST significant risk this poses?
- AIncreased storage costs due to accumulating unanalyzed log data.
- BFailure to comply with industry-specific data retention regulations.
- CInability to reconstruct events for forensic investigations.
- DDelayed detection and response to security incidents or operational issues.
Show answer & explanationAnswer & explanation
Correct answer: D. Delayed detection and response to security incidents or operational issues.
Collecting logs without reviewing them means that critical indicators of security incidents or operational problems will go unnoticed, leading to significant delays in detection and response.
Why the other options are wrong
- A. While increased storage costs are a consequence, the operational and security impact of unreviewed logs is far more significant.
- B. Retention is about how long logs are kept, not whether they are reviewed. This is a separate concern.
- C. Logs being collected means they are available for reconstruction, but without review, the *initiation* of a forensic investigation would be delayed.
Log Monitoring & Analysis
The process of systematically reviewing and analyzing system-generated logs to identify security threats, operational issues, and performance problems.
- Crucial for early detection of incidents.
- Aids in troubleshooting and performance tuning.
- Often involves automated tools (SIEM) for efficiency.
Memory trick: Logs unreviewed are like treasure maps unread; you know treasure exists but can't find it.