nerdexam
EC-Council

112-51 · Question #2

Below are the various steps involved in the creation of a data retention policy. 1.Understand and determine the applicable legal requirements of the organization 2.Ensure that all employees…

The correct answer is B. 3 -- >1 -- >4 -- >5 -- >2. The correct sequence of steps involved in the creation of a data retention policy is 3 -> 1 -> 4 -> 5 ->2. This is based on the following description of the data retention policy creation process from the web search results: Build a team: To design a data retention policy, you…

Network Security Management

Question

Below are the various steps involved in the creation of a data retention policy. 1.Understand and determine the applicable legal requirements of the organization 2.Ensure that all employees understand the organization's data retention policy 3.Build a data retention policy development team 4.ldentify and classify the data to be included in the data retention policy 5.Develop the data retention policy Identify the correct sequence of steps involved.

Options

  • A3 -- >2 -- >5 -- >4 -- >1
  • B3 -- >1 -- >4 -- >5 -- >2
  • C1 -- >3 -- >4 -- >2 -- >5
  • D1 -- >5 -- >4 -- >2 -- >3

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    79% (30)
  • C
    5% (2)
  • D
    13% (5)

Explanation

The correct sequence of steps involved in the creation of a data retention policy is 3 -> 1 -> 4 -> 5 ->2. This is based on the following description of the data retention policy creation process from the web search results: Build a team: To design a data retention policy, you need a team of industry experts, such as legal, IT, compliance, and business representatives, who can contribute their knowledge and perspectives to the policy. The team should have a clear leader who can coordinate the tasks and communicate the goals and expectations. Determine legal requirements: The team should research and understand the applicable legal and regulatory requirements for data retention that affect the organization, such as GDPR, HIPAA, PCI DSS, etc. The team should also consider any contractual obligations or industry standards that may influence the data retention policy. Identify and classify the data: The team should inventory and categorize all the data that the organization collects, stores, and processes, based on their function, subject, or type. The team should also assess the value, risk, and sensitivity of each data category, and determine the appropriate retention period, format, and location for each data category. Develop the data retention policy: The team should draft the data retention policy document that outlines the purpose, scope, roles, responsibilities, procedures, and exceptions of the data retention policy. The policy should be clear, concise, and consistent, and should reflect the legal and business requirements of the organization. The policy should also include a data retention schedule that specifies the retention period and disposition method for each data category. Ensure that all employees understand the organization's data retention policy: The team should communicate and distribute the data retention policy to all the relevant employees and stakeholders, and provide training and guidance on how to comply with the policy. The team should also monitor and enforce the policy, and review and update the policy regularly to reflect any changes in the legal or business environment.

Topics

#data retention policy#policy development#compliance#data classification

Community Discussion

No community discussion yet for this question.

Full 112-51 Practice