ISC2 Certified in Cybersecurity (CC)Security OperationsMedium
A financial institution is required by regulatory compliance to maintain an immutable record of all transactions for seven years. After this period, the data must be irretrievably destroyed. Which security operations concept dictates the duration for which this data must be kept and subsequently disposed of?
- AData classification
- BData handling
- CData retention
- DSecure disposal
Show answer & explanationAnswer & explanation
Correct answer: C. Data retention
Data retention policies define the period for which specific data types must be stored, often driven by legal or regulatory requirements, and also dictate when and how that data should be disposed of.
Why the other options are wrong
- A. Data classification categorizes data by sensitivity, but doesn't define how long it is kept.
- B. Data handling covers how data is managed securely, but 'data retention' specifically addresses the duration.
- D. Secure disposal is the method of destruction, which is a consequence of retention policy, but retention defines the 'when'.
Data Retention
The policies and procedures that govern how long an organization must keep different types of data.
- Driven by legal, regulatory, and business requirements.
- Impacts storage costs and risk exposure.
- Defines the lifespan of data before disposal.
Memory trick: Retain data as long as needed, then shred it.