Information held in systems, devices or any other storage media is to be deleted once it is no longer needed. Purpose: avoid sensitive information being exposed unnecessarily and meet legal, regulatory and contractual deletion requirements. Guidance: sensitive information should not be kept longer than necessary, to limit unwanted disclosure. When deleting from systems, applications and services, choose a method such as electronic overwriting or cryptographic erasure that fits business needs and the law, record the results as evidence, and obtain evidence of deletion from any deletion service provider. Where an outside party holds the organization's information for it, consider writing deletion requirements into the agreements for the period of service and its end. In line with the data retention policy and the law, delete sensitive information that is no longer needed by configuring systems to destroy it securely (for example after a retention period or on a subject access request); clearing out old versions, duplicates and temporary files in every location; using approved secure deletion software so that specialist recovery or forensic tools cannot retrieve it; using approved, certified disposal providers; and using mechanisms suited to the media, such as degaussing magnetic drives. For cloud services, check whether the provider's deletion method is acceptable and use it or ask the provider to delete, automating deletion under policy where possible, with logs to track or verify deletion depending on sensitivity. Remove hard drives and memory from equipment returned to vendors before it leaves the premises. Because some devices such as smartphones can only be securely wiped by destruction or built-in reset functions, choose the method according to the classification of what they hold, and apply 7.14 when destroying devices physically. A formal deletion record helps when investigating a possible leak. Other information: ISO/IEC 27017 addresses user data deletion in cloud services and ISO/IEC 27555 addresses PII deletion.
This control maps to 71 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.