A company has a data retention policy requiring customer transaction records to be kept for 7 years. After 7 years, the data should be destroyed. Which phase of the data lifecycle governs this action?
Destroying customer data is the definitive and irreversible process of rendering information unreadable and unrecoverable from all storage media. This action directly fulfills a data retention policy's requirement to eliminate data once its specified retention period has expired, ensuring compliance and mitigating future risks. Proper destruction methods prevent unauthorized access or recovery of sensitive information.
Why this answer
The destroy phase of the data lifecycle explicitly governs the secure disposal of data once its retention period ends. In this scenario, after 7 years, the policy mandates destruction, so the action falls under the Destroy phase. This phase ensures data is irrecoverable and compliant with legal and regulatory requirements.
Exam trap
CISSP often tests the confusion between archiving and destruction; candidates may think archiving implies eventual destruction, but archiving is a separate phase focused on long-term retention, while destruction is the final, irreversible step.
How to eliminate wrong answers
Option A (Use) is wrong because it refers to the active utilization of data during its lifecycle, not its disposal. Option B (Share) is wrong because it involves distributing data to authorized parties, not destroying it. Option C (Archive) is wrong because archiving is the long-term storage of data for retention, not its final destruction.