id: "SR-12" title: "Component Disposal" family: "SR" family_name: "Supply Chain Risk Management" sort_id: "sr-12" priority: "P1" implementation_level: "organization"
Statement
Dispose of {{ insert: param, sr-12_odp.01 }} using the following techniques and methods: {{ insert: param, sr-12_odp.02 }}.
Guidance
Data, documentation, tools, or system components can be disposed of at any time during the system development life cycle (not only in the disposal or retirement phase of the life cycle). For example, disposal can occur during research and development, design, prototyping, or operations/maintenance and include methods such as disk cleaning, removal of cryptographic keys, partial reuse of components. Opportunities for compromise during disposal affect physical and logical data, including system documentation in paper-based or digital files; shipping and delivery documentation; memory sticks with software code; or complete routers or servers that include permanent media, which contain sensitive or proprietary information. Additionally, proper disposal of system components helps to prevent such components from entering the gray market.
Assessment Objective
{{ insert: param, sr-12_odp.01 }} are disposed of using {{ insert: param, sr-12_odp.02 }}.
Supply chain risk management policy and procedures
supply chain risk management plan
disposal procedures addressing supply chain protection
media disposal policy
media protection policy
disposal records for system components
documentation of the system components identified for disposal
documentation of the disposal techniques and methods employed for system components
system security plan
other relevant documents or records
Organizational personnel with system component disposal responsibilities
organizational personnel with information security responsibilities
organizational personnel with supply chain protection responsibilities
Organizational techniques and methods for system component disposal
mechanisms supporting and/or implementing system component disposal