GV.SC-10.116

Does your organization have a documented process for the timely return and secure disposal of assets containing organizational data?

Explanation

Asset recovery and disposal is the concern: whether a documented process ensures that devices and media holding organizational data are returned or securely destroyed once no longer needed. Without proper asset return and disposal processes, organizational data may remain accessible to unauthorized individuals, potentially leading to data breaches or compliance violations.

Evidence could include a documented asset return/disposal policy, exit checklists for departing employees, certificates of destruction from approved vendors, asset disposal logs, or records of media sanitization that comply with standards such as NIST SP 800-88.

Implementation Example

Verify that assets containing the organization's data are returned or properly disposed of in a timely, controlled, and safe manner

ID: GV.SC-10.116

Context

Function
GV: GOVERN
Category
GV.SC: Cybersecurity Supply Chain Risk Management
Sub-Category
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

Related questions