Exam CISA All QuestionsBrowse all questions from this exam
Question 837

Which of the following is MOST important to consider when establishing the retention period for customer data within a specific database or application?

    Correct Answer: D

    When establishing the retention period for customer data within a specific database or application, the minimum regulatory requirements are the most important consideration. Ensuring compliance with regulatory requirements is crucial as it helps avoid potential legal and financial penalties. Regulatory guidelines ensure that data is retained for a necessary period to protect customer rights and adhere to industry standards. Other factors like enterprise classification level, system performance, and hardware capacity can be managed or adjusted, but regulatory compliance is mandatory and non-negotiable.

Discussion
SwallowsOption: D

While hardware capacity (Option C) is a consideration for data storage and management, it is typically not as critical as ensuring compliance with minimum regulatory requirements. Hardware capacity can be adjusted or expanded to accommodate data retention needs, but non-compliance with regulatory requirements can have far-reaching consequences for an organization's legal and regulatory standing. Therefore, adherence to regulatory requirements should be the MOST important consideration when establishing the retention period for customer data within a specific database or application.