id: "SI-14(02)" title: "Non-persistent Information" family: "SI" family_name: "System and Information Integrity" sort_id: "si-14.02" priority: "P1" implementation_level: "organization" parent: "SI-14" enhancement: True
{{ insert: param, si-14.02_odp.01 }} ; and
Delete information when no longer needed.
Guidance
Retaining information longer than is needed makes the information a potential target for advanced adversaries searching for high value assets to compromise through unauthorized disclosure, unauthorized modification, or exfiltration. For system-related information, unnecessary retention provides advanced adversaries information that can assist in their reconnaissance and lateral movement through the system.
Assessment Objective: {{ insert: param, si-14.02_odp.01 }} is performed;
Assessment Objective: information is deleted when no longer needed.
System and information integrity policy
system and information integrity procedures
procedures addressing non-persistence for system components
system design documentation
system configuration settings and associated documentation
system audit records
system security plan
other relevant documents or records
Organizational personnel responsible for ensuring that information is and remains non-persistent
organizational personnel with information security responsibilities
Organizational processes for ensuring that information is and remains non-persistent
automated mechanisms supporting and/or implementing component and service refreshes