ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your organization is finalizing an enterprise retention schedule for transactional logs that contain customer PII after acquiring a subsidiary in another legal jurisdiction. One regulation requires keeping the data for three years, while another mandates seven. To remain compliant company-wide, which retention period should be documented for this data set?
Three years, because keeping data longer than necessary increases privacy risk.
Five years, balancing legal mandates with operational efficiency.
Seven years, because the policy must satisfy the most stringent applicable legal requirement across jurisdictions.
Retain indefinitely until harmonized regulations are issued by both jurisdictions.
When different jurisdictions impose conflicting retention requirements, the organization must satisfy the most stringent (longest) mandate so that it does not violate any applicable law or regulation. Selecting the shorter three-year period would breach the seven-year mandate, while averaging or retaining data indefinitely would either still break the stricter law or conflict with storage-limitation principles that require data not be kept longer than necessary.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PII and why is it important in compliance regulations?
Open an interactive chat with Bash
Why is the longest retention period chosen in conflicting regulation scenarios?
Open an interactive chat with Bash
How can organizations balance legal mandates and storage-limitation principles?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .