NIST SP 800-88
Third-Party Providers

NIST SP 800-88 NISTSP88-6: Third-Party Sanitization Providers and Vendor Qualification

Manage third-party sanitization providers per NIST SP 800-88 Rev 1 Chapter 3 Section 3.5 + Section 4.6.4. Third-party providers used for sanitization (on-site or off-site destruction services + decommissioning vendors + IT asset disposition firms) must be qualified covering (a) capability to perform required sanitization methods per Section 2.5 with documented procedures + equipment + personnel training, (b) certifications and standards (NAID AAA Certification + R2 / R2v3 Responsible Recycling + e-Stewards + ISO/IEC 27001 + sector-specific), (c) information security controls applied to media in transit and at vendor facility, (d) chain of custody procedures documented and auditable, (e) sub-contractor management with flow-down of all requirements, (f) liability insurance + indemnification + breach notification clauses in contract. Vendor performance must be monitored via (a) periodic audit + site visit + sampling of sanitization output, (b) Certificate of Sanitization provided per media batch, (c) Service Level Agreements with measurable performance criteria, (d) incident response coordination protocols. Multi-source vendor strategy reduces single-point-of-failure risk for large-volume disposition.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.