Building on the migration plan, the decommissioning plan should include: (1) an impact analysis; (2) notification to service providers, users and customers; (3) notice of decommissioning to every relevant interface and interconnection; (4) a timeframe, plan and schedule; (5) data integrity and validation checks ahead of archiving; (6) redeployment or transfer of equipment and other assets; (7) transfer or cancellation of licences; (8) removal of redundant equipment and software; (9) removal of redundant cables and termination equipment; (10) removal of any security enhancements or emanation control equipment; (11) return or safe disposal of that emanation control equipment or those security enhancements; (12) updates to system configurations such as switches and firewalls; (13) sanitisation of equipment and media, including cloud-based data and services (covered later in the chapter); (14) disposal of equipment and media (covered later in the chapter); (15) any legal considerations when ending supply or service contracts; (16) updates to the asset register; and (17) retraining or redeployment of support staff.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.