nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #156

Which of these is a COMMON mistake made when implementing record retention policies?

The correct answer is C. Applying the longest retention periods to the information. A very common mistake is applying the longest possible retention period to all records (C) as a 'safe' default. This is problematic because retaining data longer than legally required increases storage costs, expands legal discovery exposure (more data can be subpoenaed), and…

Security Principles

Question

Which of these is a COMMON mistake made when implementing record retention policies?

Options

  • ANot labeling the type of information to be retained
  • BNot categorizing the type of information to be retained
  • CApplying the longest retention periods to the information
  • DApplying shorter retention periods to the information

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    11% (4)
  • C
    84% (32)
  • D
    3% (1)

Explanation

A very common mistake is applying the longest possible retention period to all records (C) as a 'safe' default. This is problematic because retaining data longer than legally required increases storage costs, expands legal discovery exposure (more data can be subpoenaed), and raises privacy compliance risks (e.g., GDPR mandates data minimization). Best practice is to apply the minimum legally required retention period appropriate to each data type, not a blanket maximum.

Topics

#Record Retention#Data Governance#Compliance#Information Management

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice