What to Provide
The data classification, retention and disposal procedures.
Evidence Format
Word/PDF document
Additional Guidance
These procedures are commonly known as your "data handling process" and are typically documented as part of your information security policies. The procedures should capture the following:
Roles and responsibilities with regards to data classification and handling.
Defining the data the organization captures and identifying the data's level of classification (i.e. public, sensitive, confidential).
Including guidance on the use, storage and disposal of sensitive data.
Retention requirements for all classifications of data
Disposal requirements for organization and customer data
Explanation of how customer data deletions are formally processed, documented, and tracked
Associated Unified Control ID | Associated Framework Control |
CTRL-896 | LCL-30 |