Control Mapping Readerplace a control, see the map

SOC2-P4.3 P4.3 Securely disposing of personal information

SOC2-P4.3 in SOC 2 (the AICPA 2017 Trust Services Criteria with the revised points of focus). All SOC 2 controls held. Open SOC 2 on the standards site.

The control as we hold it

P4.3 Securely disposing of personal information. Personal information is disposed of securely in line with privacy objectives. Points of focus: deletion requests are captured and the related information flagged for destruction; information no longer retained is anonymised, disposed of or destroyed in a way that prevents loss, theft, misuse or unauthorised access; and policies and procedures destroy information identified for destruction.

Reviewed and closest counterparts in the other frameworks

Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.

HIPAA Security Rule

NIST SP 800-53 Rev 5

What an auditor commonly asks for

General guidance for this control area (domain: P - Privacy), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control