An IS auditor is reviewing how a retail company protects stored payment card data. The company states it encrypts card numbers using AES-256, but the auditor finds that the database encryption keys are stored in a plaintext configuration file on the same application server as the encrypted data. Which of the following is the auditor's PRIMARY concern?
When the decryption key sits in plaintext on the same host as the ciphertext, a single server compromise yields both, so encryption provides little protection against that threat. The control objective for stored card data is to keep keys separate from data and from the application, typically in a key management system or hardware security module (HSM), which this configuration fails to do.
Why this answer
Encryption only reduces risk if the key is protected independently of the ciphertext and the host that processes it. A plaintext key file on the same application server means a single compromise exposes both data and key, nullifying the protection. Proper key management places keys in a dedicated key management system or hardware security module with strict access controls, separation from data, and documented lifecycle procedures.
Exam trap
The trap here is focusing on the strength of the encryption algorithm or on rotation schedules while overlooking that the key is stored in cleartext beside the data, which collapses the entire control.