Certified Information Systems Auditor (CISA) — Question 1415
Which of the following should be the PRIMARY basis for procedures to dispose of data securely?
Answer options
- A. Type of media used for data storage
- B. Environmental regulations
- C. Classification of data
- D. Data retention policy
Correct answer: C
Explanation
The classification of data is crucial for determining how to securely dispose of it, as different types of data may have varying privacy and security requirements. The other options, while relevant, do not directly address the sensitivity and regulatory needs of the data itself, which should guide disposal procedures.