Data Retention Policy for Compliance and Destruction
A company needs to keep the fewest records possible, meet compliance needs, and ensure destruction of records that are no longer needed. Which of the following best describes the policy that meets these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the ability to distinguish between general security policies and specific lifecycle management rules, specifically highlighting that retention policies handle both storage duration and mandatory disposal.
A retention policy defines the duration for which records are kept and mandates their secure destruction when no longer needed, balancing compliance with data minimization. This page explains why this is the correct answer (C) among the given options.
Learners often select 'Security policy' because it covers broad protection, but fail to recognize that only a retention policy explicitly governs the timeline of existence and subsequent destruction of records.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A retention policy is the specific governance document that dictates how long data must be kept to satisfy legal or regulatory obligations and when it should be securely destroyed. By establishing these timeframes, organizations can adhere to the principle of data minimization, keeping the fewest records possible while ensuring compliance. The inclusion of destruction procedures in the policy directly addresses the requirement to eliminate unnecessary data.Why the Other Options Are Wrong
A security policy provides broad guidelines for protecting information assets but does not specify timelines for data lifecycle management. A classification policy organizes data by sensitivity levels to determine appropriate handling controls, not retention periods. An access control policy defines who can interact with data and how, but it does not govern how long the data exists or its eventual disposal.Community Comment Notes
The community consensus strongly supports option C, noting that retention policies are designed to specify data duration and disposal procedures. As user Hs1208 noted, "A retention policy is designed to specify the duration for which records or data should be retained and the procedures for their disposal when they are no longer needed." Similarly, salah112 emphasized that these policies help minimize retained data while enhancing security and privacy through secure destruction.Exam Strategy
When a question mentions 'how long' data is kept or 'destruction' of old records, immediately look for keywords related to lifecycle or retention. Distinguish between policies that define access (who) versus those that define time (when).
Frequently Asked Questions
Why isn't a security policy the best answer?
Security policies are broad frameworks for protecting assets. They do not typically include specific operational directives on how long data must be retained or the technical steps for its destruction.
Does a retention policy cover legal compliance?
Yes, retention policies are primarily driven by legal and regulatory requirements. They ensure data is kept only as long as necessary to satisfy these laws before being destroyed.