id: "SI-12(03)" title: "Information Disposal" family: "SI" family_name: "System and Information Integrity" sort_id: "si-12.03" priority: "P1" implementation_level: "organization" parent: "SI-12" enhancement: True
Statement
Use the following techniques to dispose of, destroy, or erase information following the retention period: {{ insert: param, si-12.3_prm_1 }}.
Guidance
Organizations can minimize both security and privacy risks by disposing of information when it is no longer needed. The disposal or destruction of information applies to originals as well as copies and archived records, including system logs that may contain personally identifiable information.
Assessment Objective: {{ insert: param, si-12.03_odp.01 }} are used to dispose of information following the retention period;
Assessment Objective: {{ insert: param, si-12.03_odp.02 }} are used to destroy information following the retention period;
Assessment Objective: {{ insert: param, si-12.03_odp.03 }} are used to erase information following the retention period.
System and information integrity policy
system and information integrity procedures
personally identifiable information processing policy
personally identifiable information processing procedures
records retention and disposition policy
records retention and disposition procedures
laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to information disposal
media protection policy
media protection procedures
system audit records
audit findings
information disposal records
system security plan
privacy plan
privacy impact assessment
privacy risk assessment documentation
other relevant documents or records
Organizational personnel with information and records management, retention, and disposition responsibilities
organizational personnel with information security and privacy responsibilities
network administrators
Organizational processes for information disposition
automated mechanisms supporting and/or implementing information disposition