A new Chief Information Officer (CIO) created a group to write a data retention policy based on applicable laws. Which of the following is the PRIMARY motivation for the policy?
Correct Answer: B
The primary motivation for writing a data retention policy based on applicable laws is to dispose of data in order to limit liability. A data retention policy is a document that defines the rules and guidelines for retaining and disposing of the data that is created, received, or maintained by an organization. A data retention policy is based on various factors, such as the business needs, the legal requirements, the regulatory compliance, and the security risks of the data. The main purpose of a data retention policy is to dispose of the data that is no longer needed, used, or relevant for the organization, in order to limit the liability that may arise from keeping the data. For example, if the data is subject to litigation, discovery, or breach, the organization may face legal, financial, or reputational consequences. By disposing of the data according to the data retention policy, the organization can reduce the exposure and damage of the data, and avoid unnecessary costs and penalties.
References: CISSP All-in-One Exam Guide, Eighth Edition, Chapter 1: Security and Risk Management, page
21. CISSP Practice Exam | Boson, Question 9.