CISA Question of the Day: Data Retention and Disposal

CISA exam practice question — CISA Question of the Day: Data Retention and Disposal

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Protection of Information Assets.

Question

During an audit of a mid-sized company, you find that business units retain large volumes of email, documents, and backups indefinitely because there is no formal retention policy or automated disposition process. Which control would most effectively reduce legal, privacy, and storage cost risks associated with excessive data retention?

  • A. Implement and enforce a formal data retention and disposal schedule mapped to legal and regulatory requirements, supported by automated disposition and documented exceptions
  • B. Require encryption of all archived backups and removable media to protect stored data until manual deletion is performed
  • C. Rely on quarterly manual reviews by business unit owners to identify records for deletion and submit disposal requests to IT
  • D. Add contractual requirements for third-party storage providers to perform secure disposal and provide destruction certificates on request
Show the answer and explanation

Correct answer: A. Implement and enforce a formal data retention and disposal schedule mapped to legal and regulatory requirements, supported by automated disposition and documented exceptions

The best control is a formal retention and disposal schedule tied to legal and regulatory requirements, combined with automated disposition and documented exceptions. This provides authoritative retention periods, reduces human error, ensures timely deletion, and creates an audit trail (consistent with NIST SP 800-88 and good information governance). Encryption alone (option B) protects confidentiality but does not remove risk from indefinite retention or legal discovery. Quarterly manual reviews (option C) are error-prone, inconsistent and do not ensure timely enforcement. Contractual disposal clauses (option D) are important for third-party risk but do not address internal retention practices or automation.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.