フォレンジック調査の後、組織はシステムとネットワーク全体にわたって電子データを効果的に保護するための包括的なポリシーと手順の導入に注力します。これらのポリシーは、適用される法律、規制、および運用基準への準拠を確保するとともに、将来の監査、調査、または法的手続きに備えてデータの整合性を確保するように設計されています。この段階では、データの保持、アクセス管理、および長期保存に関する明確なガイドラインを確立することを目的としています。
このアクティビティは、電子情報開示リファレンス モデル (EDRM) サイクルのどの段階に相当しますか?
正解:B
According to the CHFI v11 objectives and the Electronic Discovery Reference Model (EDRM) framework, the activity described in this scenario corresponds to the Information Governance stage. Information governance is the foundational phase of the EDRM cycle and focuses on establishing policies, procedures, controls, and standards to manage electronic information throughout its lifecycle. This includes defining data retention schedules, access control policies, compliance requirements, preservation rules, and audit readiness.
In CHFI v11, information governance is emphasized as a proactive and strategic function that ensures an organization is prepared for future investigations, audits, litigation, or regulatory inquiries. By implementing governance controls after an investigation, organizations strengthen forensic readiness, reduce legal risk, and ensure that electronic data remains reliable, authentic, and admissible as evidence.
The other options do not accurately match the described activity. Disposal (Option A) refers to defensible deletion after legal hold requirements expire. Collection (Option C) involves acquiring data for analysis, while Identification (Option D) focuses on locating potentially relevant data sources. None of these address long- term policy creation or enterprise-wide data control.
The CHFI v11 Exam Blueprint explicitly includes Information Governance within the eDiscovery process, highlighting its role in compliance, risk mitigation, and evidence integrity management, making Option B the correct and exam-aligned answer