Retention is a security control
Deleting data is a security measure, even though it never appears on a controls list.
Data you no longer hold cannot be breached, requested, subpoenaed or misused. A retention schedule that is actually enforced does more for the worst-case size of an incident than most detective controls, and it costs less. It is filed under records management, which is why security teams rarely champion it.
More on Data security
- Classification should change handlingThe label throws the points
- Tokenisation changes what systems need to holdHand over the ticket, not the coat
- Data lineage explains where sensitive data travelsFollow the dye
- Data residency is not automatic securityThe line goes round the building
- Data access logs need object contextRead a record. Which one?
- DLP can match data patterns but cannot reliably infer the business purpose of a transferIt reads the shape, not the reason
