ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your U.S.-based company is rolling out a customer-data retention control for a SaaS offering that will serve EU residents. To ensure the implementation strategy aligns simultaneously with internal policy, GDPR, and the NIST SP 800-53 moderate baseline, which action is the most effective first step?
Submit a capital funding request to purchase additional storage capacity for longer retention periods.
Schedule a change control board session to add the retention control to the project timeline.
Enroll system administrators in data-retention training so they understand the new procedures.
Create a Data Retention Mapping Matrix that links each policy, GDPR, and NIST SP 800-53 retention obligation to specific implementation tasks.
Building a detailed Data Retention Mapping Matrix-also called a retention register or retention schedule-lets the team list each data type and system, map every retention obligation from corporate policy, relevant GDPR articles, and applicable NIST SP 800-53 controls, and translate them into concrete implementation tasks (labeling, archiving, deletion, auditing). Having this single source of mapped requirements verifies that the planned control will satisfy all organizational, regulatory, and framework mandates. The other actions (requesting additional storage funding, scheduling a change-control meeting, or launching training) may be useful later but do not themselves establish multi-layer requirements alignment.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Data Retention Mapping Matrix?
Open an interactive chat with Bash
How does GDPR impact data retention policies?
Open an interactive chat with Bash
What is NIST SP 800-53 and how does it relate to data retention?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .