← Back to catalog
SI-12(3)

Information Disposal

System and Information Integrity (SI)
Baselines
Low · Not includedModerate · Not includedHigh · Not included
Description

Use the following techniques to dispose of, destroy, or erase information following the retention period: [assignment].

Discussion

Organizations can minimize both security and privacy risks by disposing of information when it is no longer needed. The disposal or destruction of information applies to originals as well as copies and archived records, including system logs that may contain personally identifiable information.

Implementation guidance

No content available.

CSF 2.0 crosswalk

No CSF mappings exist for this control.