ISC2 CISSP (Certified Information Systems Security Professional)Asset SecurityMedium

A financial services company is preparing for an audit of its data retention policies. The auditor is specifically interested in how the company ensures compliance with legal and regulatory requirements for retaining transaction records, which mandate a minimum retention period of seven years. Which of the following is the MOST critical aspect for the company to demonstrate to the auditor regarding its data retention practices?

  1. AThe implementation of blockchain technology for immutable record keeping.
  2. BThe use of advanced data compression techniques for archived records.
  3. CA documented and consistently enforced data retention schedule aligned with legal mandates.
  4. DThe ability to instantly retrieve any archived record within seconds.
Show answer & explanation

Correct answer: C. A documented and consistently enforced data retention schedule aligned with legal mandates.

For an audit, the most critical aspect is demonstrating that a formal, documented data retention schedule exists, that it accurately reflects legal and regulatory requirements (like the seven-year mandate), and that it is consistently applied and enforced throughout the organization. This shows governance and compliance.

Why the other options are wrong

  • A. Blockchain is an advanced technology for immutability but is not a universal requirement for data retention compliance and may not be necessary or practical for all transaction records.
  • B. Compression is for storage efficiency, not directly for compliance with retention periods.
  • D. While quick retrieval is desirable for business operations, the audit's focus is on the *retention period compliance*, not retrieval speed.

Data Retention Schedule

A documented policy that specifies how long different types of data must be kept, based on legal, regulatory, and business requirements, and how it should be disposed of.

  • Essential for legal and regulatory compliance.
  • Guides data lifecycle management.
  • Must be consistently enforced and auditable.

Memory trick: Show the schedule, prove you follow the law.

More Asset Security questions