Certified Information Systems Auditor (CISA) — Question 791
An organization has implemented a distributed security administration system to replace the previous centralized one. Which of the following presents the GREATEST potential concern?
Answer options
- A. A distributed security system is inherently a weak security system.
- B. The new system will require additional resources.
- C. Security procedures may be inadequate to support the change.
- D. End-user acceptance of the new system may be difficult to obtain.
Correct answer: C
Explanation
The correct answer is C because a distributed security administration system relies heavily on proper security procedures to function effectively. If these procedures are not adequately adapted to the new setup, it can lead to vulnerabilities. The other options, while they present concerns, do not pose as direct a risk to the effectiveness of the security as inadequate procedures do.