A data retention policy is a documented rule set that defines how long an organization keeps each category of information and what happens when that period ends. It specifies retention periods, storage locations, and the disposal method, tying each decision to a legal, regulatory, or business justification.
Good retention balances two opposing pressures. Keep data too long and you expand your attack surface, storage costs, and e-discovery exposure; delete it too soon and you may break a law or destroy evidence. A hospital might retain patient records for years to meet HIPAA and state rules, while an analytics team purges raw logs after ninety days. The step people forget is defensible disposal: when the clock runs out, data must actually be destroyed in a verifiable way, not merely forgotten on a backup tape. Legal holds override the schedule and freeze deletion during litigation.
Why does a data retention policy matter for the CISSP exam?
It belongs to Domain 2, Asset Security, which covers the full data lifecycle. Candidates should link retention to data classification, ownership roles, privacy law, and secure destruction methods such as purging and cryptographic erasure.