ExamGecko
Question list
Search
Search

Related questions











Question 400 - CISA discussion

Report
Export

Which of the following is the BEST reason to implement a data retention policy?

A.
To limit the liability associated with storing and protecting information
Answers
A.
To limit the liability associated with storing and protecting information
B.
To document business objectives for processing data within the organization
Answers
B.
To document business objectives for processing data within the organization
C.
To assign responsibility and ownership for data protection outside IT
Answers
C.
To assign responsibility and ownership for data protection outside IT
D.
To establish a recovery point detective (RPO) for (toaster recovery procedures
Answers
D.
To establish a recovery point detective (RPO) for (toaster recovery procedures
Suggested answer: A

Explanation:

The best reason to implement a data retention policy is to limit the liability associated with storing and protecting information. A data retention policy is a document that defines how long data should be kept by an organization and how they should be disposed of when they are no longer needed.A data retention policy should comply with the applicable laws and regulations that govern the data retention requirements and obligations of organizations, such as tax laws, privacy laws, or industry standards4.Implementing a data retention policy can help to limit the liability associated with storing and protecting information by reducing the amount of data that need to be stored and secured, minimizing the risk of data breaches or leaks, ensuring compliance with legal or contractual obligations, and avoiding potential fines or penalties for non-compliance5. The other options are less relevant or incorrect because:

B . Documenting business objectives for processing data within the organization is not a reason to implement a data retention policy, as it is more related to data governance than data retention. Data governance refers to the policies, procedures, and controls that define how data are collected, used, managed, and shared within an organization.Data governance helps to ensure that data are aligned with business objectives and support decision making6.

C . Assigning responsibility and ownership for data protection outside IT is not a reason to implement a data retention policy, as it is more related to data accountability than data retention. Data accountability refers to the identification and assignment of roles and responsibilities for data protection among different stakeholders within an organization.Data accountability helps to ensure that data are handled appropriately and securely by authorized parties7.

D . Establishing a recovery point objective (RPO) for disaster recovery procedures is not a reason to implement a data retention policy, as it is more related to data backup than data retention. Data backup refers to the process of creating copies of data that can be restored in case of data loss or corruption.Data backup helps to ensure that data are available and recoverable in case of disaster8.RPO is a measure of the maximum amount of data that can be lost or acceptable in case of disaster9.Reference:Data Retention Policy - ISACA,Data Retention - ISACA,Data Governance - ISACA,Data Accountability - ISACA,Data Backup - ISACA,Recovery Point Objective - ISACA

asked 18/09/2024
KRISHNA SUMAN
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first