Control Mapping Readerplace a control, see the map

SOC2-CC6.5 CC6.5 Protecting data on assets until disposal

SOC2-CC6.5 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.

The control as we hold it

CC6.5 Protecting data on assets until disposal. Logical and physical protection over physical assets is withdrawn only once the data and software on them can no longer be read or recovered and are no longer needed. Points of focus: data and software on equipment due for disposal are identified and made unreadable; and, as revised in 2022, data and software are removed, deleted or made inaccessible on any device the organisation, its vendors or its staff own once they are no longer needed there or the device leaves the organisation's control. (Device recovery from leavers sits under CC6.4.)

Reviewed and closest counterparts in the other frameworks

Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.

HIPAA Security Rule

NIST SP 800-53 Rev 5

What an auditor commonly asks for

General guidance for this control area (domain: CC - Common Criteria (Security)), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control