Under active development Content is continuously updated and improved

DM-14Secure Disposal of Media

>Control Description

Organization securely erases media containing decommissioned restricted data and obtains a certificate or log of erasure; media pending erasure are stored within a secured facility.

Theme

Process

Type

Preventive

Policy/Standard

Data Management Policy

>Implementation Guidance

1. Ensure that requirements for destroying media containing decommissioned restricted data are defined and documented. 2. Ensure that the requirements for maintaining a log of such activities is defined. 3. Ensure that appropriate records are maintained for such activities. 4. Ensure a security facility is designated to store such media prior to erasure. 5. Ensure a certificate of erasure is obtained for such media post erasure completion.

>Testing Procedure

1. Inspect and validate whether requirements for destroying media containing decommissioned restricted data are defined and documented. 2. Inspect and validate that the requirements for maintaining a log of such activities is defined. 3. Validate that appropriate records are maintained for such activities. 4. For a sample of records, validate that a certificate of erasure was obtained for such media post erasure completion.

>Audit Artifacts

E-DM-01
E-DM-17

>Framework Mappings

Cross-framework mappings provided by Adobe CCF Open Source under Creative Commons License.

Ask AI

Configure your API key to use AI features.