ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityHard

A global e-commerce company is updating its data retention policy for customer transaction records. Due to varying legal and regulatory requirements across different jurisdictions, the company must ensure that data is not kept longer than legally mandated, but also not deleted prematurely if still required for business operations or legal hold. What is the MOST critical element to establish for an effective data retention policy in this complex environment?

  1. AClear ownership for each data type and its retention schedule.
  2. BAutomated data deletion scripts for expired records.
  3. CEnd-to-end encryption for all data at rest and in transit.
  4. DCentralized storage for all customer transaction records.
Show answer & explanation

Correct answer: A. Clear ownership for each data type and its retention schedule.

In a complex environment with varying requirements, establishing clear ownership for each data type and its associated retention schedule is paramount. The data owner is responsible for understanding the legal, regulatory, and business requirements for their data and defining the retention periods. Without this foundational clarity, automated deletion scripts might remove necessary data, centralized storage doesn't define retention, and encryption is a control, not a policy element.

Why the other options are wrong

  • B. Automated deletion is a technical control that relies on a well-defined policy, not the policy's foundation.
  • C. Encryption is a security control, not a policy element that defines how long data is kept.
  • D. Centralized storage is an architectural decision, not directly a policy element for retention periods.

Data Retention Policy Ownership

Designating specific data owners who are accountable for defining and enforcing retention schedules for their respective data types, especially crucial in complex regulatory environments.

  • Assigns responsibility for retention decisions.
  • Ensures compliance with legal and business needs.
  • Foundation for automated retention processes.

Memory trick: Owner's Watch, Data's Clock, Compliance's Lock.

More Asset Security questions