CAS-002 · Question #122
The security administrator at a company has received a subpoena for the release of all the email received and sent by the company Chief Information Officer (CIO) for the past three years. The…
The correct answer is B. The company backup logs and archives. Before assuming non-compliance with a subpoena, the administrator should check backup logs and archives because the missing years of email may still exist outside the live mail server.
Question
The security administrator at a company has received a subpoena for the release of all the email received and sent by the company Chief Information Officer (CIO) for the past three years. The security administrator is only able to find one year's worth of email records on the server and is now concerned about the possible legal implications of not complying with the request. Which of the following should the security administrator check BEFORE responding to the request?
Options
- AThe company data privacy policies
- BThe company backup logs and archives
- CThe company data retention policies and guidelines
- DThe company data retention procedures
How the community answered
(28 responses)- A18% (5)
- B71% (20)
- C7% (2)
- D4% (1)
Why each option
Before assuming non-compliance with a subpoena, the administrator should check backup logs and archives because the missing years of email may still exist outside the live mail server.
Data privacy policies govern how information is handled and protected, but they do not reveal the physical or logical location of historical email backup copies.
Email systems routinely back up and archive messages on a schedule that retains data well beyond the active server's retention window - the two missing years of email could exist in tape backups, email archiving appliances, or offline storage, and confirming their existence before responding to a legal request prevents a false declaration of non-compliance.
Data retention policies define how long data should be kept, but consulting the policy does not confirm whether the archived email copies actually exist in a backup system.
Data retention procedures describe the process for storing data, but like the policy itself, they cannot confirm whether specific backup copies of the missing emails are present.
Concept tested: Email backup and archive verification for legal hold compliance
Source: https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.