ISACA Certified Information Systems Auditor (CISA) ExamDomain 4: Information Systems Operations and Business ResilienceEasy
An IS auditor is evaluating an organization's data management practices, specifically focusing on data retention. The auditor discovers that several critical financial records are being deleted after five years, while regulatory requirements mandate a seven-year retention period. Which of the following is the MOST significant risk associated with this finding?
- ANon-compliance with legal and regulatory obligations, potentially leading to fines.
- BIncreased storage costs due to inefficient data archiving.
- CDifficulty in performing historical data analysis for business intelligence.
- DReduced system performance due to an overgrown database size.
Show answer & explanationAnswer & explanation
Correct answer: A. Non-compliance with legal and regulatory obligations, potentially leading to fines.
Deleting records prematurely, when regulatory requirements mandate a longer retention period, directly exposes the organization to legal non-compliance, which can result in significant fines and legal penalties. This is the most critical risk among the options.
Why the other options are wrong
- B. This scenario describes premature deletion, which would reduce, not increase, storage costs, making it incorrect.
- C. While true, the primary and most severe risk when regulatory mandates are violated is legal non-compliance.
- D. Premature deletion would reduce database size, not increase it, making this option incorrect.
Data Retention Policy
A documented policy outlining how long specific types of data must be kept to meet legal, regulatory, and business requirements.
- Ensures compliance with laws and regulations.
- Balances business needs with storage costs.
- Specifies data types, retention periods, and disposal methods.
Memory trick: Ignoring retention rules invites legal woes and big fines.