ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

A company policy mandates that all customer data must be securely deleted from all storage media, including backups, within 30 days after the customer terminates their service. For hard drives, this involves degaussing or physical destruction. For cloud-based storage, it involves verified cryptographic erasure. This policy directly addresses which aspect of data handling?

  1. AData classification
  2. BSecure disposal
  3. CData encryption
  4. DData retention
Show answer & explanation

Correct answer: B. Secure disposal

The scenario focuses on the methods and timeline for permanently removing data from storage media once it is no longer needed, which is the definition of secure disposal.

Why the other options are wrong

  • A. Data classification categorizes data's sensitivity, not its end-of-life removal.
  • C. Data encryption protects data while in use or at rest, but secure disposal ensures its complete removal.
  • D. Data retention defines *how long* data is kept, while disposal defines *how* it's removed after that period.

Secure Data Disposal

The process of permanently and irrecoverably removing data from storage media to prevent unauthorized access or recovery, adhering to organizational policies and regulatory requirements.

  • Methods include degaussing, shredding, cryptographic erasure
  • Applies to all media types (hard drives, SSDs, cloud)
  • Crucial for compliance and data privacy

Memory trick: When data's life ends, dispose of it securely.

More Security Operations questions