正解:A
The organization should implement a retention policy to ensure that financial data records are kept for three years and customer data for five years. A retention policy specifies how long different types of data should be maintained and when they should be deleted.
Retention: Ensures that data is kept for a specific period to comply with legal, regulatory, or business requirements.
Destruction: Involves securely deleting data that is no longer needed, which is part of the retention lifecycle but not the primary focus here.
Inventory: Involves keeping track of data assets, not specifically about how long to retain data.
Certification: Ensures that processes and systems meet certain standards, not directly related to data retention periods.