CRISC - Information Technology and Security (20% of the exam) - Section 4.8

Apply data privacy and data protection principles across the data lifecycle.

Apply data privacy and data protection principles - including data classification and data lifecycle management - to govern how personal and sensitive information is collected, stored, used, and disposed of. Recognise that privacy risk varies across lifecycle phases and that classification drives the control requirements at each stage.

Data privacyData protectionData lifecycle managementData classification

Practice question for this objective

Free sampleInformation Technology and Securitymedium

A bank discovers that backups of decommissioned customer accounts are retained indefinitely on tape because no rule defines when they should be destroyed. A risk practitioner is advising on how to manage privacy risk at the disposal stage of the data lifecycle. Which control would most directly reduce the privacy risk created by this practice?

  • AEncrypt every backup tape at rest so that any personal data on the retained media stays unreadable to anyone without the decryption key.
  • BMove the backup tapes to an off-site vault with stricter physical access controls than the current on-premises tape library provides.
  • CCatalogue each backup tape in an asset register so the bank always knows which decommissioned accounts are stored on which media.
  • DDefine and enforce a retention schedule with secure disposal so personal data is destroyed once its lawful retention period ends. Correct
A defined retention schedule with secure disposal limits how long personal data persists, reducing privacy risk at the disposal stage. Privacy risk at end of life comes from holding personal data longer than any lawful basis allows. A retention schedule fixes how long each data type may be kept and pairs it with secure destruction, so decommissioned account data is purged on time rather than sitting on tape indefinitely.

Why A is wrong: Encryption protects confidentiality of the tapes and feels like a strong fix, but it leaves the data in existence indefinitely, so it does not address the disposal failure driving the risk.

Why B is wrong: Tighter physical access reduces theft risk and sounds prudent, yet the underlying problem is that the data is never disposed of, which relocation does nothing to solve.

Why C is wrong: An accurate inventory improves visibility and is worth having, but knowing where data sits does not trigger its destruction, so the indefinite retention risk remains.

Why D is correct: A retention schedule with secure disposal sets when data must be destroyed and enforces it, removing the indefinitely held records that create the privacy exposure at end of life.

See more CRISC practice questions, answers explained.

Exam traps in Information Technology and Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Compress and encrypt the records in transit so that the customer account data cannot be intercepted while it moves between the two countries.

    Why it is wrong: Encryption in transit protects against interception and is good practice, but it does not address the lawfulness of moving data to a regime with weaker protection, which is the transfer issue here.

  • Storage limitation, because keeping the member contact details on the claims platform for longer than the agreed retention window raises the privacy exposure.

    Why it is wrong: Storage limitation concerns how long data is kept, which sounds relevant, but the scenario describes reuse for a new purpose rather than excessive retention of the records.

  • Grant developers temporary read access to the live production database during testing so they always work against the most current customer records.

    Why it is wrong: Live access gives realistic data but exposes real customer records to a non-production setting, which raises rather than reduces the privacy risk the practitioner must contain.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.