Event Log Aggregation System Risk Management
An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?
Community Votes
67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the auditor's ability to prioritize data integrity and availability (completeness) over data confidentiality (encryption) when reviewing log systems for risk management purposes.
The question addresses risk management in event log aggregation systems, where community consensus identifies completeness testing as the primary concern over encryption or formatting issues.
Many candidates choose D (Encryption) because they associate security primarily with confidentiality. However, if logs are incomplete, forensic analysis and compliance reporting become impossible, representing a higher operational risk.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Completeness is the foundational requirement for any audit trail or log aggregation system. If log data is missing due to failures in collection or transmission, the organization loses visibility into security events, making it impossible to detect incidents or prove compliance. Without complete data, other controls like encryption are moot because there is no reliable record to protect.Why the Other Options Are Wrong
While data encryption (D) protects confidentiality, it does not ensure that the logs exist or are accurate. Batch processing (B) is a valid technical method and not inherently risky unless latency requirements are violated. Non-normalized data (C) may affect analysis efficiency but does not compromise the existence or integrity of the log records themselves.Community Comment Notes
Comments highlight the tension between confidentiality and integrity. While some users argue for encryption (D), others correctly point out that logs fall under the integrity category of security. The consensus emphasizes that without completeness, the log system fails its primary purpose: providing a reliable history of events.Official Reference
Exam Strategy
When auditing log systems, always prioritize the 'Availability' and 'Integrity' of the data first. Ask yourself: 'Can we even see the events?' before asking 'Are the events protected?'. Completeness is a prerequisite for all other security functions.
Frequently Asked Questions
Why is completeness more important than encryption for logs?
Encryption protects data at rest/transit, but if logs are incomplete, you cannot detect breaches or meet compliance. Integrity/availability is the primary goal of logging.
Does batch processing pose a risk to log integrity?
Batch processing can introduce latency but does not inherently compromise integrity. It is a design choice, whereas missing logs (incompleteness) is a critical control failure.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →