The best answer is C. Reviewing key compromise detection activities.
In a PKI, the greatest practical risk in key management is failure to detect and respond when keys are compromised. If compromise is not detected promptly, confidentiality, integrity, authentication, and nonrepudiation can all be undermined. ISACA materials discussing PKI and cryptographic transition stress the importance of certificate revocation, rollout strategies, and careful key management because compromise of keys directly affects trust in the system.
Option D is important, but documentation alone does not prove that compromise can be detected in practice. Option B may help monitoring, but it is narrower than the broader control objective of detecting compromised keys. Option A is not a core audit concern in comparison. From a CISA perspective, the most important focus is whether the organization can detect, contain, and revoke trust when keys are exposed or misused.
References (Official ISACA):
ISACA Journal, Building Resilient Security in the Age of Quantum Computing — discusses PKI key management complexity and certificate revocation as critical control considerations.
Submit