id: "CP-09(07)" title: "Dual Authorization for Deletion or Destruction" family: "CP" family_name: "Contingency Planning" sort_id: "cp-09.07" priority: "P2" implementation_level: "organization" parent: "CP-09" enhancement: True


Statement

Enforce dual authorization for the deletion or destruction of {{ insert: param, cp-09.07_odp }}.

Guidance

Dual authorization ensures that deletion or destruction of backup information cannot occur unless two qualified individuals carry out the task. Individuals deleting or destroying backup information possess the skills or expertise to determine if the proposed deletion or destruction of information reflects organizational policies and procedures. Dual authorization may also be known as two-person control. To reduce the risk of collusion, organizations consider rotating dual authorization duties to other individuals.

Assessment Objective

dual authorization for the deletion or destruction of {{ insert: param, cp-09.07_odp }} is enforced.

Contingency planning policy

procedures addressing system backup

contingency plan

system design documentation

system configuration settings and associated documentation

system generated list of dual authorization credentials or rules

logs or records of deletion or destruction of backup information

system security plan

other relevant documents or records

Organizational personnel with system backup responsibilities

organizational personnel with information security responsibilities

Mechanisms supporting and/or implementing dual authorization

mechanisms supporting and/or implementing the deletion/destruction of backup information