Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A compliance officer is reviewing the organization's data handling policies to ensure adherence to regulations like GDPR and HIPAA. They need to define how long certain types of data must be kept and when they must be securely disposed of. Which compliance concept is the officer primarily focusing on?

  1. AData Retention and Deletion
  2. BData Minimization
  3. CData Sovereignty
  4. DData Classification
Show answer & explanation

Correct answer: A. Data Retention and Deletion

Data Retention and Deletion policies define the periods for which different types of data must be kept and the secure methods for their disposal when no longer needed or legally required. This directly matches the scenario's focus on 'how long certain types of data must be kept and when they must be securely disposed of' in adherence to regulations.

Why the other options are wrong

  • B. Data Minimization focuses on collecting only necessary data, not its lifespan after collection.
  • C. Data Sovereignty relates to data being subject to laws of the country where it is stored.
  • D. Data Classification categorizes data by sensitivity, which informs retention but isn't the retention itself.

Data Retention and Deletion

Policies and procedures that dictate how long specific types of data must be stored and the secure methods for their permanent removal or destruction.

  • Driven by legal, regulatory, and business requirements.
  • Ensures compliance and reduces data risk.
  • Includes secure disposal methods like shredding or cryptographic erasure.

Memory trick: Data Retention and Deletion is like managing a library's books: knowing when to keep them and when to discard them securely.

More Describe the concepts of security, compliance, and identity questions