nerdexam
Isaca

CISM · Question #924

Which of the following is the BEST way for an information security manager to provide evidence that data has been retained for the appropriate period in accordance with applicable laws and…

The correct answer is B. Obtaining copies of the retention configurations. Copies of the retention configurations (e.g., system settings, retention rules) provide concrete, verifiable evidence that retention controls are implemented to enforce the required retention periods, rather than merely documenting intent or requirements.

Submitted by chen.hong· Apr 18, 2026Information Security Governance

Question

Which of the following is the BEST way for an information security manager to provide evidence that data has been retained for the appropriate period in accordance with applicable laws and regulations?

Options

  • AConducting a data inventory
  • BObtaining copies of the retention configurations
  • CProviding reports on requirements mapped from the regulations
  • DPublishing retention periods in an information management policy

How the community answered

(42 responses)
  • A
    2% (1)
  • B
    71% (30)
  • C
    10% (4)
  • D
    17% (7)

Explanation

Copies of the retention configurations (e.g., system settings, retention rules) provide concrete, verifiable evidence that retention controls are implemented to enforce the required retention periods, rather than merely documenting intent or requirements.

Topics

#Data Retention#Regulatory Compliance#Audit Evidence#Information Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice