PR.IP-6.1: The organization shall ensure that its critical system's data is destroyed according to policy.
Disposal actions include media sanitization actions (See PR.DS-3)
There are two primary types of media in common use:
oHard copy media (physical representations of information)
oElectronic or soft copy media (the bits and bytes contained in hard drives, random access memory (RAM), read-only memory (ROM), disks, memory devices, phones, mobile computing devices, networking equipment…)
Description
The organization shall ensure that its critical system's data is destroyed according to policy.
PR.IP-6.2
PR.IP-6.2: Sanitation processes shall be documented and tested.
Sanitation processes include procedures and equipment.
Consider applying non-destructive sanitization techniques to portable storage devices.
Consider sanitation procedures in proportion to confidentiality requirements.
Description
Sanitation processes shall be documented and tested.