The organization shall ensure that its critical system's data is destroyed according to policy.
Guidance
- Disposal actions include media sanitization actions (See PR.DS-3)
- There are two primary types of media in common use:
- Hard copy media (physical representations of information)
- Electronic or soft copy media (the bits and bytes contained in hard drives, random access
memory (RAM), read-only memory (ROM), disks, memory devices, phones, mobile
computing devices, networking equipment…)
Sanitation processes shall be documented and tested.
Guidance
- Sanitation processes include procedures and equipment.
- Consider applying non-destructive sanitization techniques to portable storage devices.
- Consider sanitation procedures in proportion to confidentiality requirements.
Papers containing sensitive information should be disposed of in an agreed manner, for example, using a shredder or by incineration.
Unnecessary media should be disposed of in a safe, industry-accepted manner (such as by incineration, shredding or wiping) in accordance with formal procedures. Media that requires safe disposal must be clearly marked.
Data destroyed in accordance with the process should not be recoverable, even by forensic means.
Limiting the retention time is one of the principles of the processing of personal data. If the retention period of the data is not provided by law, when determining the retention periods, the following must be taken into account, for example:
Describe your own process for evaluating retention periods.
Organization must document the retention periods for data sets and their possible archiving process (including archiving method, location or destruction). At the end of the retention period, the data must be archived or destroyed without delay in a secure manner.
When destroying data contained in data systems, the following points should be taken into account:
The process of archiving or destroying data is defined in connection with the documentation, and the owner of the data is responsible for its implementation.