Which issue must a comprehensive email policy specifically address?

Prepare for the CISA Domain 2 Exam. Use flashcards and multiple-choice questions with hints and explanations to get exam ready!

A comprehensive email policy should specifically address retention because it involves the guidelines and procedures for how long emails should be kept, the manner of storing them, and the processes for their eventual deletion. Proper email retention management ensures compliance with legal and regulatory requirements, protects sensitive information, and helps mitigate risks associated with data loss or breaches.

Establishing a retention policy aids in organizing emails in a manner that addresses business needs while also ensuring that unnecessary data is not kept longer than required, which can lead to potential vulnerabilities. The retention policy also supports efficient data retrieval for legal purposes, audits, or investigations.

In contrast, while other aspects such as recovery, rebuilding, or reuse may be relevant in certain contexts, they do not encompass the fundamental requirement of how emails should be managed over time, which is critical for governance and compliance in an organization.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy