Question 1 of 30
A multinational corporation, \"Aethelred Analytics,\" is reviewing its information lifecycle management practices for customer data. They have identified a dataset containing personally identifiable information (PII) that was created on January 15, 2023. This data is subject to a mandatory five-year retention period due to regulatory requirements, including the General Data Protection Regulation (GDPR), and internal corporate policy. The data is no longer actively used for business operations but must be retained for its full duration. Aethelred Analytics is considering various methods for the eventual disposition of this dataset. Which of the following approaches best aligns with the principles of information governance for securely and compliantly managing this sensitive data at the end of its active use but within its retention period?
Securely and irreversibly destroy the data on or after January 15, 2028, ensuring the destruction process is documented.
Anonymize the data to remove all PII and then retain it indefinitely for potential future research.
Archive the data to a cold storage solution, accessible only by a limited number of senior compliance officers.
Perform a standard digital deletion of the data files, assuming the operating system will overwrite the space.

Preparing for ISO 24143:2022 - Information Governance Professional? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free