← Back to catalog
SI-12(3)
Information Disposal
System and Information Integrity (SI)
Baselines
Low · Not includedModerate · Not includedHigh · Not included
Description
Use the following techniques to dispose of, destroy, or erase information following the retention period: [assignment].
Discussion
Organizations can minimize both security and privacy risks by disposing of information when it is no longer needed. The disposal or destruction of information applies to originals as well as copies and archived records, including system logs that may contain personally identifiable information.
Implementation guidance
No content available.
CSF 2.0 crosswalk
No CSF mappings exist for this control.