SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
SOC2-CC6.5 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.
The control as we hold it
CC6.5 Protecting data on assets until disposal. Logical and physical protection over physical assets is withdrawn only once the data and software on them can no longer be read or recovered and are no longer needed. Points of focus: data and software on equipment due for disposal are identified and made unreadable; and, as revised in 2022, data and software are removed, deleted or made inaccessible on any device the organisation, its vendors or its staff own once they are no longer needed there or the device leaves the organisation's control. (Device recovery from leavers sits under CC6.4.)
Reviewed and closest counterparts in the other frameworks
Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.
HIPAA Security Rule
- 164.308(a)(3)(ii)(C) Termination Procedures (Addressable) (closest match)
- 164.308(a)(7)(ii)(A) Data Backup Plan (Required) (closest match)
- 164.310(d)(1) Device and Media Controls (Standard) (closest match)
- 164.310(d)(2)(i) Disposal (Required) (closest match)
- 164.310(d)(2)(ii) Media Re-use (Required) (closest match)
- 164.310(d)(2)(iii) Accountability (Addressable) (closest match)
- 164.310(d)(2)(iv) Data Backup and Storage (Addressable) (closest match)
- 164.316(b)(1) Documentation (Standard) (closest match)
NIST SP 800-53 Rev 5
- NIST800-AT-4 AT-4 Training Records (closest match)
- NIST800-MP-1 MP-1 Policy and Procedures (closest match)
- NIST800-MP-2 MP-2 Media Access (closest match)
- NIST800-MP-6 MP-6 Media Sanitization (closest match)
- NIST800-MP-7 MP-7 Media Use (closest match)
- NIST800-MP-8 MP-8 Media Downgrading (closest match)
- NIST800-PE-5 PE-5 Access Control for Output Devices (closest match)
- NIST800-PE-16 PE-16 Delivery and Removal (closest match)
What an auditor commonly asks for
General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.
- the board or management oversight record
- the risk assessment and its treatment
- the access-review and change-approval records
- the monitoring, logging and incident records