
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Protection of Information Assets.
Question
During an audit of a mid-sized company, you find that business units retain large volumes of email, documents, and backups indefinitely because there is no formal retention policy or automated disposition process. Which control would most effectively reduce legal, privacy, and storage cost risks associated with excessive data retention?
Show the answer and explanation
Correct answer: A. Implement and enforce a formal data retention and disposal schedule mapped to legal and regulatory requirements, supported by automated disposition and documented exceptions
The best control is a formal retention and disposal schedule tied to legal and regulatory requirements, combined with automated disposition and documented exceptions. This provides authoritative retention periods, reduces human error, ensures timely deletion, and creates an audit trail (consistent with NIST SP 800-88 and good information governance). Encryption alone (option B) protects confidentiality but does not remove risk from indefinite retention or legal discovery. Quarterly manual reviews (option C) are error-prone, inconsistent and do not ensure timely enforcement. Contractual disposal clauses (option D) are important for third-party risk but do not address internal retention practices or automation.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
