id: "CP-09(07)" title: "Dual Authorization for Deletion or Destruction" family: "CP" family_name: "Contingency Planning" sort_id: "cp-09.07" priority: "P2" implementation_level: "organization" parent: "CP-09" enhancement: True
Statement
Enforce dual authorization for the deletion or destruction of {{ insert: param, cp-09.07_odp }}.
Guidance
Dual authorization ensures that deletion or destruction of backup information cannot occur unless two qualified individuals carry out the task. Individuals deleting or destroying backup information possess the skills or expertise to determine if the proposed deletion or destruction of information reflects organizational policies and procedures. Dual authorization may also be known as two-person control. To reduce the risk of collusion, organizations consider rotating dual authorization duties to other individuals.
Assessment Objective
dual authorization for the deletion or destruction of {{ insert: param, cp-09.07_odp }} is enforced.
Contingency planning policy
procedures addressing system backup
contingency plan
system design documentation
system configuration settings and associated documentation
system generated list of dual authorization credentials or rules
logs or records of deletion or destruction of backup information
system security plan
other relevant documents or records
Organizational personnel with system backup responsibilities
organizational personnel with information security responsibilities
Mechanisms supporting and/or implementing dual authorization
mechanisms supporting and/or implementing the deletion/destruction of backup information