ExamGecko
Question list
Search
Search

Question 492 - CISM discussion

Report
Export

An organization has identified a large volume of old data that appears to be unused. Which of the following should the information security manager do NEXT?

A.
Consult the record retention policy.
Answers
A.
Consult the record retention policy.
B.
Update the awareness and training program.
Answers
B.
Update the awareness and training program.
C.
Implement media sanitization procedures.
Answers
C.
Implement media sanitization procedures.
D.
Consult the backup and recovery policy.
Answers
D.
Consult the backup and recovery policy.
Suggested answer: A

Explanation:

The next thing that the information security manager should do after identifying a large volume of old data that appears to be unused is to consult the record retention policy. The record retention policy is a document that defines the types, formats, and retention periods of data that the organization needs to keep for legal, regulatory, operational, or historical purposes. By consulting the record retention policy, the information security manager can determine if the old data is still required to be stored, archived, or disposed of, and how to do so in a secure and compliant manner.

asked 01/10/2024
Wissem M'RAD
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first