Data life cycle controls from creation to destruction
Place data in its lifecycle stage, choose the control objective and evidence, and diagnose handoff gaps for ISC scenarios.
The decision that earns the point
Identify the objective before choosing the control
Data lifecycle management governs data from creation or collection through validation, use, sharing, storage, retention, archival, and secure disposition. The control objective changes by stage: quality and provenance matter at creation, authorization and integrity during use, recoverability and retention during storage, and verified destruction at the end. A policy is incomplete unless ownership and evidence follow the data across each handoff.
Exam use
ISC can test data ownership, quality, classification, lineage, access, transmission, backup, retention, legal hold, archival, disposition, and monitoring over lifecycle transitions.
Your scratch-paper plan
Solve it in three moves
- 1
Locate the lifecycle stage
Identify whether the data is being created, transformed, used, shared, stored, retained, archived, or destroyed.
NIST SP 800-53 Rev. 5.1: Security and Privacy Controls - 2
Choose the stage-specific objective
Match quality, authorization, confidentiality, integrity, availability, retention, or disposition to the stated risk.
NIST SP 800-53 Rev. 5.1: Security and Privacy Controls - 3
Prove the handoff
Inspect ownership, lineage, approvals, logs, reconciliation, retention records, or destruction evidence at the transition between stages.
NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
Worked problem
Work the facts before choosing the answer
Customer records must be retained for seven years. The production system deletes them after 18 months, but an analytics warehouse keeps ungoverned copies indefinitely and the backup catalog does not identify either population.
CPAPass exam analysis using the stated assumptions
Show the work
The production rule violates the required retention period, while the warehouse and backups violate controlled disposition. The issue is a cross-system lifecycle inventory and ownership failure, not one database setting.
Rule source: NIST SP 800-53 Rev. 5.1: Security and Privacy ControlsAnswer
Map all copies, apply the seven-year schedule and any holds consistently, preserve required records, and produce evidence when eligible copies are destroyed.
Rule source: NIST SP 800-53 Rev. 5.1: Security and Privacy ControlsDo it now
Test the same decision with a fresh question
Start with free ISC practice. Create an account only when you want the 5-day no-card CPAPass trial and continued section practice.
The trap and the repair
Common trap
Reviewing only the production database misses extracts, interfaces, warehouses, archives, and backups. Treating retention as keep everything forever also increases exposure and defeats authorized disposition.
Repair
Create a copy-and-owner inventory, attach the retention trigger and hold status, and require deletion or archival evidence for every governed repository.
Authority and scope boundary
The Blueprint controls the tested ISC data-lifecycle scope, while NIST SP 800-53 supports the concrete access, integrity, retention, media, logging, and disposition controls used in the examples. This route owns lifecycle stages and handoffs. Database schemas, SQL privileges, and detailed privacy requirements remain with their specific owners.
2026 Uniform CPA Examination Blueprints and NIST SP 800-53 Rev. 5.1: Security and Privacy Controls were reviewed on 2026-08-14. Check a newer authority when the effective date or facts change.
Lifecycle control map
Give every data copy an owner and an exit
The strongest lifecycle answer follows the same data through changing systems, purposes, and evidence.
| Lifecycle stage | Primary control objective | Evidence example | Authority |
|---|---|---|---|
| Create and collect | Authorized source, minimum required fields, quality, and provenance | Source validation, consent or authority record, rejected-data log | NIST SP 800-53 Rev. 5.1: Security and Privacy Controls |
| Use and transform | Accuracy, authorized purpose, lineage, and controlled change | Transformation rules, reconciliation, lineage record, access log | NIST SP 800-53 Rev. 5.1: Security and Privacy Controls |
| Store, share, and retain | Protected transfer, availability, retention, and legal-hold consistency | Encryption setting, backup test, inventory, retention and hold status | NIST SP 800-53 Rev. 5.1: Security and Privacy Controls |
| Archive and dispose | Readable preservation followed by authorized, complete destruction | Archive restore test, approval, destruction certificate, residual-copy check | NIST SP 800-53 Rev. 5.1: Security and Privacy Controls |
After a miss
Review lifecycle questions copy by copy
- 1
List every system and copy mentioned, including extracts, archives, and backups.
- 2
Assign each copy a stage, owner, required control objective, and evidence item.
- 3
Complete a new ISC scenario and test both early deletion and over-retention before choosing the answer.
Your exam workflow
- Step 1Identify the requirementIdentify whether the data is being created, transformed, used, shared, stored, retained, archived, or destroyed.NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
- Step 2Classify the factsMatch quality, authorization, confidentiality, integrity, availability, retention, or disposition to the stated risk.NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
- Step 3Apply the authorityInspect ownership, lineage, approvals, logs, reconciliation, retention records, or destruction evidence at the transition between stages.NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
- Step 4Check the outputMap all copies, apply the seven-year schedule and any holds consistently, preserve required records, and produce evidence when eligible copies are destroyed.NIST SP 800-53 Rev. 5.1: Security and Privacy Controls
Keep the next step narrow
Quick questions
What is the key rule?
Data lifecycle management governs data from creation or collection through validation, use, sharing, storage, retention, archival, and secure disposition. The control objective changes by stage: quality and provenance matter at creation, authorization and integrity during use, recoverability and retention during storage, and verified destruction at the end. A policy is incomplete unless ownership and evidence follow the data across each handoff.
How can this topic be tested on the CPA Exam?
ISC can test data ownership, quality, classification, lineage, access, transmission, backup, retention, legal hold, archival, disposition, and monitoring over lifecycle transitions.
What mistake most often changes the result?
Reviewing only the production database misses extracts, interfaces, warehouses, archives, and backups. Treating retention as keep everything forever also increases exposure and defeats authorized disposition. Create a copy-and-owner inventory, attach the retention trigger and hold status, and require deletion or archival evidence for every governed repository.
Where should I practice the decision?
After the worked example, open the ISC free-practice link and work a fresh question that tests the same decision. If the miss depends on Database controls, review that handoff before trying another set.