The correct answer is B. Inability to correlate security events in time.
The greatest risk is that storing logs only in native device formats can make centralized analysis and event correlation difficult. Different devices may use different log formats, field names, timestamp formats, event codes, and levels of detail. If logs cannot be normalized, parsed, and correlated, the organization may fail to identify patterns across systems, reconstruct incidents, or detect coordinated attacks.
ISACA explains that SIEM technology is used for real-time monitoring, correlation, and processing of security events, as well as historical analysis of log file information for investigations. ISACA also states that a SIEM solution consumes event logs from many source systems and provides a consolidated view of security activities, and that poor implementation or lack of a purpose-driven logging approach reduces the value of SIEM. ISACA’s CISA Exam Content Outline includes Operational Log Management under Domain 4 and Security Monitoring Tools and Techniques under Domain 5.
Option A is not the greatest risk because automation may still be possible even if logs are stored in native formats. Option C is not the best answer because storage cost is less significant than loss of detection, investigation, and incident-response capability. Option D is a concern for log integrity, but the question’s strongest clue is the decision to keep logs in native device formats, which most directly affects event normalization and correlation. Also, encryption mainly protects confidentiality; it does not by itself guarantee that logs cannot be modified.
Therefore, the greatest audit concern is that the organization may be unable to correlate security events accurately and timely across systems.
[References: ISACA CISA Exam Content Outline, Domains 4 and 5; ISACA Journal, The Practical Aspect: Challenges of Security Log Management; ISACA Journal, A Framework for SIEM Implementation., , ]
Submit