ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceMedium

An IS auditor is reviewing an organization's data management practices. The auditor observes that data owners are not formally assigned for several critical databases. What is the MOST significant risk associated with this weakness?

  1. AIncreased likelihood of data breaches due to inadequate security controls.
  2. BDifficulty in performing data quality checks and validation.
  3. CLack of accountability for data integrity and compliance.
  4. DChallenges in archiving and disposing of data according to retention policies.
Show answer & explanation

Correct answer: C. Lack of accountability for data integrity and compliance.

Without formally assigned data owners, there is no single individual or entity ultimately responsible for ensuring the accuracy, integrity, security, and compliance of the data, leading to a critical gap in accountability.

Why the other options are wrong

  • A. Inadequate security controls can lead to breaches, but the absence of a data owner means no one is ultimately responsible for ensuring those controls are in place and effective.
  • B. While data owners often oversee quality, the fundamental issue is accountability, which underpins all other data management activities.
  • D. Data retention and disposal are responsibilities of a data owner, but the overarching risk is the lack of accountability for *all* aspects of data management.

Data Owner

A designated individual or group responsible for the strategic decisions regarding the data, including its classification, protection, and compliance with regulations.

  • Accountable for data integrity, availability, and confidentiality.
  • Approves access and establishes data usage policies.
  • Ensures data meets business and regulatory requirements.

Memory trick: No data owner is like a ship without a captain; no one is ultimately responsible for its journey.

More Domain 4: Information Systems Operations and Business Resilience questions