← Controls / SR

SR-12 Component Disposal

Supply Chain Risk Management

Low Moderate High New in Rev 5

Description

Dispose of [Assignment: organization-defined data, documentation, tools, or system components] using the following techniques and methods: [Assignment: organization-defined techniques and methods].

Supplemental Guidance

Data, documentation, tools, or system components can be disposed of at any time during the system development life cycle (not only in the disposal or retirement phase of the life cycle). For example, disposal can occur during research and development, design, prototyping, or operations/maintenance and include methods such as disk cleaning, removal of cryptographic keys, partial reuse of components. Opportunities for compromise during disposal affect physical and logical data, including system documentation in paper-based or digital files; shipping and delivery documentation; memory sticks with software code; or complete routers or servers that include permanent media, which contain sensitive or proprietary information. Additionally, proper disposal of system components helps to prevent such components from entering the gray market.

Changes from Rev 4

New control family introduced in Rev 5

Compliance Mappings

ISO 27001:2022

A.8.10

CIS Controls v8

CIS 3.5

NIST CSF 2.0

GV.SC-10ID.AM-08

SOC 2 TSC

CC6.5

ANSSI

Hygiene.19SecNumCloud.9.3

FINMA Circular 2023/1

IV.E(83)

OSFI B-13

B-13.4.1

EU GDPR

Art.17(1)Art.28(1)Art.28(3)(g)

EU DORA

Art.28(8)Art.30(2)(g)

RBI CSF

Annex1.1

SAMA CSF

3.9

Qatar NIA

AM

IOSCO Cyber Resilience

PROT-7

FFIEC IS

II.C.14

HIPAA Security Rule

§164.310(d)(2)(i)

PCI PTS v6

GK

Solvency II

DR.274EIOPA-Cloud-GL11

FCA SYSC 13

SYSC 13.9.5

Basel SCO60

SCO60.54