ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.10: Information deletion

Information held in systems, devices or any other storage media is to be deleted once it is no longer needed. Purpose: avoid sensitive information being exposed unnecessarily and meet legal, regulatory and contractual deletion requirements. Guidance: sensitive information should not be kept longer than necessary, to limit unwanted disclosure. When deleting from systems, applications and services, choose a method such as electronic overwriting or cryptographic erasure that fits business needs and the law, record the results as evidence, and obtain evidence of deletion from any deletion service provider. Where an outside party holds the organization's information for it, consider writing deletion requirements into the agreements for the period of service and its end. In line with the data retention policy and the law, delete sensitive information that is no longer needed by configuring systems to destroy it securely (for example after a retention period or on a subject access request); clearing out old versions, duplicates and temporary files in every location; using approved secure deletion software so that specialist recovery or forensic tools cannot retrieve it; using approved, certified disposal providers; and using mechanisms suited to the media, such as degaussing magnetic drives. For cloud services, check whether the provider's deletion method is acceptable and use it or ask the provider to delete, automating deletion under policy where possible, with logs to track or verify deletion depending on sensitivity. Remove hard drives and memory from equipment returned to vendors before it leaves the premises. Because some devices such as smartphones can only be securely wiped by destruction or built-in reset functions, choose the method according to the classification of what they hold, and apply 7.14 when destroying devices physically. A formal deletion record helps when investigating a possible leak. Other information: ISO/IEC 27017 addresses user data deletion in cloud services and ISO/IEC 27555 addresses PII deletion.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 71 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 7 controls

  • 7.3.6 Access, correction and/or erasure
  • 7.4.5 PII de-identification and deletion at the end of processing
  • 7.4.6 Temporary files
  • 7.4.8 Disposal
  • 8.2 Conditions for collection and processing
  • 8.3.1 Obligations to PII principals
  • 8.4.1 Temporary files

PCI DSS 4.0 · 6 controls

  • 3.3.1.1 3.3.1.1 Full track data not retained after authorization
  • 3.3.1.2 3.3.1.2 Card verification code not retained after authorization
  • 3.3.1.3 3.3.1.3 PIN and PIN block not retained after authorization
  • 9.4.7 9.4.7 Destruction of electronic media
  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data
  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted

SOC 2 · 4 controls

  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • ISM-0348 Media sanitisation processes and procedures
  • ISM-0354 Overwriting non-volatile magnetic media
  • ISM-1735 Destroying media that fails sanitisation

ETSI EN 303 645 · 3 controls

FedRAMP High · 3 controls

  • MP-6 Media Sanitization
  • SI-12 Information Management and Retention
  • SR-12 Component Disposal (SR-12)

FedRAMP Moderate · 3 controls

  • MP-6 Media Sanitization
  • SI-12 Information Management and Retention
  • SR-12 Component Disposal (SR-12)

GDPR · 3 controls

  • GDPR-Art.17 Right to erasure (right to be forgotten)
  • GDPR-Art.25 Data protection by design and by default
  • GDPR-Art.5 Principles relating to processing of personal data

MTCS (Singapore) · 3 controls

  • 12.10 Secure disposal verification of live instances and backups
  • 12.7 Data retention
  • A.4 Disclosure: Data retention

NIST SP 800-53 Rev 5 · 3 controls

  • 31 s 31 Conditions of a covert surveillance authority, including worker access before adverse action
  • 44(2) s 44(2) Destroy or permanently de-identify surveillance records no longer needed
  • AUCDR-IS-3 Securely manage information assets over their lifecycle
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data

CIS Controls v8 · 2 controls

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

APPI · 1 control

  • APPI-A22 Accuracy and Deletion of Personal Data
  • SEC07-BP04 Define scalable data lifecycle management
  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator
  • AM-3 Ensure security of asset lifecycle management

C5 (Germany) · 1 control

CMMC 2.0 · 1 control

  • s4-5 s 4(5) Delete video data without delay once no longer needed

HIPAA Security Rule · 1 control

IEC 62443 · 1 control

  • 62443-3-3-FR4-SR-4-2 Information Persistence and Sanitisation

ISO 27001:2022 · 1 control

  • 8.10 Information deletion
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk

NIST SP 800-172 · 1 control

  • 3.14.5e Review Persistent Storage and Remove CUI No Longer Needed
  • s29-30 ss 29 to 30 Duration and conditions of the authority, and compliance with them

NY DFS 23 NYCRR 500 · 1 control

  • §500.13 Asset Management and Data Retention Requirements
  • 22.2.15.C.03 22.2.15.C.03 Safe VM decommissioning including residual data (classified)
  • P2-5.1.2 P2-5.1.2 3DS data kept only as long as needed, then purged securely

PTES · 1 control

  • PTES-4.2 Encrypt, control and destroy engagement data and evidence

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 71 it maps to, and the evidence behind each claim, over MCP and REST.