CAS-003 · Question #15
A business is growing and starting to branch out into other locations. In anticipation of opening an office in a different country, the Chief Information Security Officer (CISO) and legal team agree…
The correct answer is B. Data retention policy E. Data sovereignty policy H. Encryption standard. Meeting data lifecycle, geographic, and encryption requirements for a new international office requires a combination of retention, sovereignty, and encryption policies working together.
Question
A business is growing and starting to branch out into other locations. In anticipation of opening an office in a different country, the Chief Information Security Officer (CISO) and legal team agree they need to meet the following criteria regarding data to open the new office:
Store taxation-related documents for five years Store customer addresses in an encrypted format Destroy customer information after one year Keep data only in the customer's home country Which of the following should the CISO implement to BEST meet these requirements? (Choose three.)
Options
- ACapacity planning policy
- BData retention policy
- CData classification standard
- DLegal compliance policy
- EData sovereignty policy
- FBackup policy
- GAcceptable use policy
- HEncryption standard
How the community answered
(32 responses)- A3% (1)
- B66% (21)
- C9% (3)
- F3% (1)
- G19% (6)
Why each option
Meeting data lifecycle, geographic, and encryption requirements for a new international office requires a combination of retention, sovereignty, and encryption policies working together.
Capacity planning policy addresses storage and compute resource allocation, not data handling lifecycle, geographic residency, or encryption requirements.
A data retention policy directly addresses the requirements to store taxation documents for five years and destroy customer information after one year by defining mandatory data lifecycle rules.
A data classification standard categorizes data by sensitivity level but does not specify retention periods, geographic restrictions, or encryption implementation requirements.
A legal compliance policy is a broad governance document and does not provide the specific operational controls needed for retention schedules, data sovereignty, or encryption.
A data sovereignty policy mandates that data remain within a specific country or jurisdiction, directly satisfying the requirement to keep data only in the customer's home country.
A backup policy governs how and when data backups are created and stored, not the lifecycle, geographic location, or encryption requirements for primary data.
An acceptable use policy governs how employees and users interact with organizational systems and data, not data management, retention, or encryption requirements.
An encryption standard defines the required algorithms, key lengths, and implementation methods to ensure customer addresses are stored in an encrypted format as required.
Concept tested: Data governance policies for international compliance requirements
Source: https://csrc.nist.gov/publications/detail/sp/800-188/final
Topics
Community Discussion
No community discussion yet for this question.