CAS-002 · Question #614
A court order has ruled that your company must surrender all the email sent and received by a certain employee for the past five years. After reviewing the backup systems, the IT administrator…
The correct answer is C. Data retention policies. When a legal order requires email records beyond what backups retain, the organization must review its data retention policy, which defines how long different categories of data must be preserved.
Question
A court order has ruled that your company must surrender all the email sent and received by a certain employee for the past five years. After reviewing the backup systems, the IT administrator concludes that email backups are not kept that long. Which of the following policies MUST be reviewed to address future compliance?
Options
- ATape backup policies
- BOffsite backup policies
- CData retention policies
- DData loss prevention policies
How the community answered
(30 responses)- A3% (1)
- B3% (1)
- C93% (28)
Why each option
When a legal order requires email records beyond what backups retain, the organization must review its data retention policy, which defines how long different categories of data must be preserved.
Tape backup policies govern the media and procedures used for backup storage, but do not define the legally required duration for which data categories such as email must be kept.
Offsite backup policies address the physical location and replication of backups for disaster recovery purposes, not the minimum retention duration required for compliance.
Data retention policies define the minimum and maximum periods for which specific types of organizational data must be stored to satisfy legal, regulatory, and business requirements. If email is not retained for five years, the retention policy either fails to mandate that period or is not being enforced, and revising it ensures future compliance with similar court orders or regulations.
Data loss prevention policies are designed to detect and block unauthorized exfiltration of sensitive data, and do not govern how long data must be stored to satisfy legal or regulatory obligations.
Concept tested: Data retention policy for legal and regulatory compliance
Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
Topics
Community Discussion
No community discussion yet for this question.