An IS auditor reviewing a company's encryption practices finds that sensitive data at rest is encrypted using a symmetric key stored in the same database as the data. What is the PRIMARY concern?
-
A
Symmetric encryption is insufficient for data at rest
-
B
The encryption key and ciphertext are co-located, negating protection
-
C
The encryption algorithm may be outdated
-
D
The database lacks proper indexing for encrypted fields