Operate verification + audit + training + environmental controls per NIST SP 800-88 Rev 1 Chapter 4 Section 4.7 + Chapter 5. Verification per Section 4.7: (a) Clear verification via representative sampling and read-back testing, (b) Purge verification via sampling and laboratory verification techniques where stakes warrant, (c) Destroy verification via visual inspection + chain-of-custody documentation + photographic evidence where appropriate, (d) document verification methodology + sampling rationale + verification results per sanitization batch. Audit and continuous improvement: (a) periodic internal audit of sanitization program per Chapter 5, (b) review of Certificate of Sanitization records for completeness + accuracy + consistency, (c) trend analysis on sanitization volume + method distribution + verification failure rate + vendor performance, (d) external audit by regulator or independent assessor as required. Personnel training per Section 3.2: (a) initial training for personnel handling media for sanitization covering policy + methods + chain of custody + recordkeeping, (b) refresher training annually, (c) specialised training for sanitization technicians + ITAD vendor managers + records custodians. Environmental + Safety Controls per Section 2.5.3: (a) follow OSHA + environmental regulations for destruction methods (shredder safety + chemical handling + incineration emissions + dust + noise), (b) protect operator safety with PPE + ventilation + ergonomic equipment, (c) coordinate with sustainability + recycling programs to minimise waste.
This control maps to 91 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 91 it maps to, and the evidence behind each claim, over MCP and REST.