CISSP Practice Question: Your security team must implement a data retention policy for customer records.…
Correct Answer: A. Applicable legal and regulatory requirements governing the record type and jurisdiction
Explanation (CISSP Manager Logic):
Retention periods are primarily driven by legal and regulatory mandates — organizations cannot set minimum retention below what law requires regardless of cost, classification, or technical constraints. Regulations such as HIPAA, SOX, and PCI DSS specify mandatory minimums that override internal policy preferences.
By anchoring retention periods to legal requirements, you:
- Ensure the organization meets its mandatory legal obligations and avoids penalties for premature destruction
- Create a defensible retention schedule that withstands regulatory audit and legal discovery
- Provide the baseline from which business and risk considerations can extend (but not shorten) retention
While the other options are relevant, they fall short because:
- B: Storage costs are operational considerations that cannot override legally mandated minimum periods
- C: Classification informs sensitivity controls on retained data but does not set the retention duration
- D: Technical capabilities affect implementation but do not determine the required retention timeframe
Think like a manager:
Retention policy is a legal compliance function first — business convenience and technical limitations are constraints to engineer around, not variables that set the floor.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial