nerdexam
Isaca

CISM · Question #684

An information security manager is drafting a data protection policy for a Software as a Service (SaaS) platform. Which of the following is the MOST important consideration?

The correct answer is B. Retention requirements for customer data. Retention requirements for customer data are the most important consideration when drafting a data protection policy, as they ensure compliance with legal, regulatory, and contractual obligations while supporting data lifecycle management.

Submitted by brentm· Apr 18, 2026Information Security Program Development and Management

Question

An information security manager is drafting a data protection policy for a Software as a Service (SaaS) platform. Which of the following is the MOST important consideration?

Options

  • AThe type of storage class to be utilized
  • BRetention requirements for customer data
  • CDatabase schema for the customer master table
  • DFrequency of disaster recovery testing

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    77% (33)
  • C
    14% (6)
  • D
    2% (1)

Explanation

Retention requirements for customer data are the most important consideration when drafting a data protection policy, as they ensure compliance with legal, regulatory, and contractual obligations while supporting data lifecycle management.

Topics

#data protection policy#data retention#SaaS security#compliance

Community Discussion

No community discussion yet for this question.

Full CISM Practice