CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 987


Which of the following is MOST important to include in a data retention policy to reduce legal liabilities associated with information life cycle management?

Show Answer
Correct Answer: AD

A data retention policy aimed at reducing legal liabilities should prioritize ensuring that unnecessary data is not stored. By not retaining unnecessary data, an organization diminishes the chances of data exposure or misuse, thereby reducing the potential for legal consequences. This approach also helps in maintaining compliance with various data protection laws and regulations by ensuring only essential data is kept, thus minimizing risks associated with data breaches or unauthorized access.

Discussion

6 comments
Sign in to comment
BabaPOption: A
May 9, 2023

I am stuck between A and D

saado9Option: C
Mar 21, 2023

why not C. Ensuring that personal information is destroyed. ?

3008Option: A
Aug 19, 2023

A data retention policy is the first step in helping protect an organization’s data and avoid financial, civil, and criminal penalties that increasingly accompany poor data management practices. By ensuring that unnecessary data is not stored,

FAGFUROption: C
Nov 14, 2023

The most important element to include in a data retention policy to reduce legal liabilities associated with information life cycle management is ensuring that personal information is destroyed. This is particularly crucial for complying with privacy regulations and protecting individuals' sensitive data. The secure and proper destruction of personal information is a key component in managing legal liabilities and demonstrating compliance with data protection laws.

KAP2HURUFOption: A
Jan 1, 2024

In summary, while not storing unnecessary data (Option A) is a foundational principle of data management that can reduce overall legal liabilities, securely wiping data (Option D) is more directly focused on the specific legal risks associated with data discovery in legal proceedings. The choice between these options depends on the primary concern and specific context of the organization's data retention policy.

SwallowsOption: A
Jul 15, 2024

Not storing unnecessary data is crucial for legal risk mitigation and compliance. By minimizing the data you store, you reduce the risk of data leakage and legal liability.