NIST SP 800-88
Verification + Audit + Training + Safety

NIST SP 800-88 NISTSP88-7: Verification, Audit, Training, and Environmental/Safety Controls

Operate verification + audit + training + environmental controls per NIST SP 800-88 Rev 1 Chapter 4 Section 4.7 + Chapter 5. Verification per Section 4.7: (a) Clear verification via representative sampling and read-back testing, (b) Purge verification via sampling and laboratory verification techniques where stakes warrant, (c) Destroy verification via visual inspection + chain-of-custody documentation + photographic evidence where appropriate, (d) document verification methodology + sampling rationale + verification results per sanitization batch. Audit and continuous improvement: (a) periodic internal audit of sanitization program per Chapter 5, (b) review of Certificate of Sanitization records for completeness + accuracy + consistency, (c) trend analysis on sanitization volume + method distribution + verification failure rate + vendor performance, (d) external audit by regulator or independent assessor as required. Personnel training per Section 3.2: (a) initial training for personnel handling media for sanitization covering policy + methods + chain of custody + recordkeeping, (b) refresher training annually, (c) specialised training for sanitization technicians + ITAD vendor managers + records custodians. Environmental + Safety Controls per Section 2.5.3: (a) follow OSHA + environmental regulations for destruction methods (shredder safety + chemical handling + incineration emissions + dust + noise), (b) protect operator safety with PPE + ventilation + ergonomic equipment, (c) coordinate with sustainability + recycling programs to minimise waste.

What else in your programme already covers this

This control maps to 91 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 5 controls

BSI IT-Grundschutz · 4 controls

  • BSI-14 Vulnerability scanning and management
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

ISO/IEC 29147:2018 · 4 controls

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)

ISO 27043 · 3 controls

ISO/IEC 30111:2019 · 3 controls

ISO/SAE 21434 · 3 controls

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO/IEC 27011:2024 · 2 controls

NIST SP 800-190 · 2 controls

OWASP ASVS · 2 controls

  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP MASVS · 2 controls

  • OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates
  • OWASPMASVS-8 MASVS-PRIVACY: Privacy and Data Protection

South Korea ISMS-P · 2 controls

API 1164 · 1 control

  • CPG-5.A Vulnerability Disclosure Program
  • CJIS-10 System and Information Integrity

IEC 62443 · 1 control

ISO 13485 · 1 control

ISO 27019 · 1 control

ISO 27799 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 1 control

NIST SP 800-171 · 1 control

  • 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process
  • 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process
  • NZISM-5 Network Security, System Hardening, and Application Security

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 91 it maps to, and the evidence behind each claim, over MCP and REST.