ISACA Certified Information Systems Auditor (CISA) ExamDomain 1: Information System Auditing ProcessMedium

An IS auditor is planning an audit of a new enterprise-wide data retention and deletion policy and its implementation across various systems. The policy mandates specific retention periods for different data classifications and automated deletion processes. What is the MOST significant risk if the audit does not adequately address the policy's implementation?

  1. AIncreased software licensing costs due to data sprawl.
  2. BDifficulty in performing data recovery operations.
  3. CReduced system performance due to large data volumes.
  4. DNon-compliance with legal and regulatory data privacy requirements.
Show answer & explanation

Correct answer: D. Non-compliance with legal and regulatory data privacy requirements.

Data retention and deletion policies are frequently driven by legal and regulatory requirements (e.g., GDPR, CCPA). Failure to implement these policies correctly can lead to severe penalties, reputational damage, and legal action, making non-compliance the most significant risk.

Why the other options are wrong

  • A. Increased licensing costs are a potential operational inefficiency, but less severe than regulatory non-compliance.
  • B. Difficulty in data recovery relates to data availability, but the primary purpose of retention/deletion policies is often regulatory compliance.
  • C. Reduced system performance is an operational issue, generally less critical than legal and regulatory violations.

Regulatory Compliance Audit

A regulatory compliance audit assesses an organization's adherence to relevant laws, regulations, and industry standards, ensuring processes and controls meet mandated requirements.

  • Focuses on specific external requirements.
  • Aims to identify gaps and ensure corrective action.
  • Non-compliance can lead to legal penalties and reputational damage.

Memory trick: Policy, Procedure, Penalty: PPP of data compliance.

More Domain 1: Information System Auditing Process questions