CIS Controls v8
CIS Control 3: Data Protection

CIS Controls v8 CIS-3.5: Securely Dispose of Data

Dispose of data securely in the way the enterprise data management process describes, using a disposal process and method that match how sensitive the data is.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 66 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 8 controls

  • 6.5 Asset management
  • 6.5.3 Media handling
  • 6.8.2 Equipment
  • 7.4.5 PII de-identification and deletion at the end of processing
  • 7.4.6 Temporary files
  • 7.4.8 Disposal
  • 8.4.1 Temporary files
  • 8.4.2 Return, transfer or disposal of PII

PCI DSS 4.0 · 5 controls

  • 3.3.1.1 3.3.1.1 Full track data not retained after authorization
  • 9.4.6 9.4.6 Destruction of hard-copy materials
  • 9.4.7 9.4.7 Destruction of electronic media
  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data
  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted

FedRAMP High · 4 controls

  • MA-3(3) Maintenance Tools | Prevent Unauthorized Removal (MA-3(3))
  • MP-6 Media Sanitization
  • SI-12 Information Management and Retention
  • SR-12 Component Disposal (SR-12)

FedRAMP Moderate · 4 controls

  • MA-3(3) Maintenance Tools | Prevent Unauthorized Removal (MA-3(3))
  • MP-6 Media Sanitization
  • SI-12 Information Management and Retention
  • SR-12 Component Disposal (SR-12)

ISO 27001:2022 · 4 controls

  • 7.10 Storage media
  • 7.14 Secure disposal or re-use of equipment
  • 8.10 Information deletion
  • 8.33 Test information

ISO 27002:2022 · 4 controls

  • 5.33 Protection of records
  • 7.10 Storage media
  • 7.14 Secure disposal or re-use of equipment
  • 8.10 Information deletion

NIST SP 800-53 Rev 5 · 4 controls

APPI · 3 controls

  • APPI-A22 Accuracy and Deletion of Personal Data
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information
  • APPI-A43 Preparation of Anonymized Personal Information
  • ISM-0348 Media sanitisation processes and procedures
  • ISM-0350 Destroying media that cannot be sanitised
  • ISM-1735 Destroying media that fails sanitisation
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk

NIST SP 800-161 Rev 1 · 3 controls

SOC 2 · 3 controls

  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-P4.3 P4.3 Securely disposing of personal information

C5 (Germany) · 2 controls

CMMC 2.0 · 2 controls

HIPAA Security Rule · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • SEC07-BP04 Define scalable data lifecycle management
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data
  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator
  • AM-3 Ensure security of asset lifecycle management

ISO/IEC 42001:2023 · 1 control

  • 7.5.3 Control of documented information

NIST SP 800-172 · 1 control

  • 3.14.5e Review Persistent Storage and Remove CUI No Longer Needed

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 3: Data Protection

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-3.5 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 66 it maps to, and the evidence behind each claim, over MCP and REST.