Information deletion
Purpose
Delete information from systems, devices and media once no longer needed, to cut exposure and meet legal obligations.
How to meet this control
In short: Delete information when no longer required.
- Step 01Set retention schedules per data type aligned to the Privacy Act, contractual terms and business need, and configure systems to delete on expiry
- Step 02Use platform retention and disposal tooling such as Microsoft Purview lifecycle policies, S3 lifecycle rules or database TTL to automate deletion
- Step 03For confidential media, use secure erasure (cryptographic wipe, overwriting) or certified physical destruction rather than a simple delete
- Step 04When a deletion provider is used, obtain certificates of destruction and retain them as evidence
- Step 05For cloud data, confirm the provider deletion mechanism is acceptable and verify removal through audit logs
- Step 06Wipe or factory-reset devices and remove auxiliary storage before equipment is returned or reused
Tip: Automate retention/deletion and document the schedule.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Do not keep sensitive information longer than required, in line with retention policy and law
- ›Choose a deletion method such as overwriting or cryptographic erasure that fits needs
- ›Record deletion results as evidence, useful when investigating later leakage
- ›When using a deletion service provider, obtain proof that deletion occurred
- ›Configure systems to destroy data automatically once retention expires and remove temp files
- ›Use approved secure deletion software, certified disposal providers or methods like degaussing
- ›For cloud, confirm the provider deletion method is acceptable and verify via logs
- ›Before returning equipment, remove auxiliary storage using resets or physical destruction
Audit evidence to keep
- - Data retention and disposal schedule mapped to data types
- - Automated retention or lifecycle policy configuration screenshot
- - Certificate of destruction from a disposal provider
- - Deletion log or audit entry confirming records were removed on schedule
- - Device wipe records for returned or reused equipment
Common mistakes
- - Classifying data once and never reviewing it
- - Allowing sensitive data into test or AI tools without approval
- - Keeping data after the business or legal need has expired
Owner, cadence, and proof
Assign one accountable owner for A.8.10. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.