Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
DSP - Data Security & Privacy Lifecycle Management

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-DSP-16: Data Retention and Deletion

Manage data retention, archiving and deletion against business requirements and applicable law, so data is neither kept longer nor destroyed sooner than allowed.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 50 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

  • CIS-15.7 Securely Decommission Service Providers
  • CIS-3.1 Establish and Maintain a Data Management Process
  • CIS-3.4 Enforce Data Retention
  • CIS-3.5 Securely Dispose of Data

APPI · 3 controls

  • APPI-A22 Accuracy and Deletion of Personal Data
  • APPI-A35 Request for Cessation of Use, Erasure or Cessation of Third Party Provision
  • APPI-A41 Preparation and Handling of Pseudonymized Personal Information

EU AI Act · 3 controls

  • EUAI-Art.18 Documentation keeping
  • EUAI-Art.19 Automatically generated logs
  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox

ISO 27701:2019 · 3 controls

  • 7.4.5 PII de-identification and deletion at the end of processing
  • 7.4.7 Retention
  • 8.4.2 Return, transfer or disposal of PII

PCI DSS 4.0 · 3 controls

  • 10.5.1 10.5.1 Keep logs 12 months, latest three months online
  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data
  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted

SOC 2 · 3 controls

  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • AUCDR-IS-3 Securely manage information assets over their lifecycle
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data

C5 (Germany) · 2 controls

  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept
  • C5-PI-03 Secure deletion of data

FedRAMP High · 2 controls

  • MP-6 Media Sanitization
  • SI-12 Information Management and Retention

FedRAMP Moderate · 2 controls

  • MP-6 Media Sanitization
  • SI-12 Information Management and Retention

GDPR · 2 controls

  • GDPR-Art.17 Right to erasure (right to be forgotten)
  • GDPR-Art.5 Principles relating to processing of personal data

ISO 27001:2022 · 2 controls

  • 5.33 Protection of records
  • 8.10 Information deletion

ISO 27002:2022 · 2 controls

  • 5.33 Protection of records
  • 8.10 Information deletion
  • NIST-CSF-GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • SEC07-BP04 Define scalable data lifecycle management
  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator
  • APP-11 APP 11 - Security of personal information
  • CFTC-SS-20 Production of System Safeguards Books and Records

CMMC 2.0 · 1 control

DORA · 1 control

HIPAA Security Rule · 1 control

ISO 22301:2019 · 1 control

  • 7.5.3 Control of documented information
  • 03.14.08 Information Management and Retention

NIST SP 800-172 · 1 control

  • 3.14.5e Review Persistent Storage and Remove CUI No Longer Needed

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DSP - Data Security & Privacy Lifecycle Management

You are reading one control. How much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 have you already done?

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 CCM-DSP-16 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 140 of 197 Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 12 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 50 it maps to, and the evidence behind each claim, over MCP and REST.