ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessEasy

An IS auditor is planning an audit of a new enterprise-wide data retention and deletion policy. The policy mandates specific retention periods for various data types, including sensitive customer information, and requires automated deletion after these periods expire. Which of the following is the MOST important consideration for the auditor during the planning phase?

  1. AThe level of user training provided on the new policy and its implications.
  2. BThe impact of the policy on system performance and storage capacity.
  3. CThe legal and regulatory requirements applicable to data retention and deletion.
  4. DThe cost-effectiveness of the automated deletion solution.
Show answer & explanation

Correct answer: C. The legal and regulatory requirements applicable to data retention and deletion.

For a data retention and deletion policy, especially one involving sensitive customer information, compliance with legal and regulatory requirements (e.g., GDPR, HIPAA, PCI DSS) is paramount. Any non-compliance could lead to severe penalties, making it the most critical consideration during planning.

Why the other options are wrong

  • A. User training is an implementation control, but the policy itself must first be legally sound.
  • B. System performance and storage are operational concerns, important but not as critical as legal compliance for a data retention policy.
  • D. Cost-effectiveness is a business concern, secondary to legal compliance in an audit of this nature.

Regulatory Compliance Audit

An audit focused on assessing an organization's adherence to relevant laws, regulations, and industry standards.

  • Protects against legal penalties.
  • Ensures ethical and responsible operations.
  • Often mandated for specific industries.

Memory trick: When planning, always check the 'rulebook' first.

More Domain 1: Information System Auditing Process questions