What Should Be Done With Information No Longer Required by Business Objectives?

Information that is no longer required to support business objectives should be:

  1. securely deleted according to the disposal policy. Source Reference Answer
  2. transferred and archived to an enterprise data vault.
  3. managed according to the retention policy.
  4. recoverable according to the business impact analysis (BIA).

Community Votes

A
50%
C
50%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests whether candidates recognize that retention policies govern the entire data lifecycle, making them the authoritative control over when and how information is eventually disposed of.

This CRISC question evaluates data lifecycle governance, emphasizing that all information handling must follow formal retention policies rather than arbitrary disposal or archiving. Community consensus highlights that policy-driven management supersedes tactical execution steps.

Candidates frequently select A (securely deleted) because it appears to be the direct solution, but fail to realize that disposal methods and timing must be formally dictated by the retention policy.

Community Discussion (4 comments)

Sara98 👍 2 Selected: A
Securely deleted according to the disposal policy: When information is no longer required to support business objectives, it should be securely deleted to protect sensitive data and comply with data protection regulations. This action prevents unauthorized access and potential data breaches.
lferolm 👍 1
I think A is included in C.
Silvias4 👍 2 Selected: C
Agree - C. managed according to the retention policy
ramy2277 👍 2
C. managed according to the retention policy.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C is correct because retention policies act as the primary governance framework that dictates both the duration information must be kept and the procedures for its eventual disposition. In CRISC, organizations must adhere to documented schedules that satisfy legal, regulatory, and operational requirements before any data is removed. The retention policy inherently authorizes and structures the transition from active use to archival or destruction.

Why the Other Options Are Wrong

Option A represents a tactical execution step that is actually subordinate to and mandated by the retention policy, making it incomplete as a standalone answer. Option B violates data minimization principles by preserving information explicitly deemed unnecessary, which unnecessarily increases liability and storage overhead. Option D incorrectly applies the Business Impact Analysis, which prioritizes system recovery during disasters rather than managing routine data lifecycle transitions.

Community Comment Notes

The evenly split votes reflect a common ISACA dilemma between governance documentation and immediate technical actions. Comment 4 accurately observes that secure deletion is functionally encompassed within the retention policy framework, reinforcing why C is the superior choice. Comment 1 correctly identifies security benefits but misses the hierarchical testing point where policy always trumps procedure. Always anchor your selection to the controlling document rather than the resulting action.

Official Reference

Exam Strategy

Prioritize selecting the overarching policy, standard, or governance framework over specific technical procedures when answering lifecycle or compliance scenarios. ISACA consistently rewards answers that demonstrate structured, auditable processes rather than isolated operational steps.

Related Analysis

Practice All CRISC Questions

Access 332 questions with complete answers and detailed explanations.

View Full CRISC Practice Test →

← Back to CRISC Study Guide