Free compliance framework explorer — browse controls, evidence, and implementation guidance.Subscribe for updates →
BETA
SOC 247
ITSP.10.17198
ISO 42001soon
ISO 27001soon
Browse
Ctrl+K
33 controls
CC1.1
Commitment to integrity and ethical values
Control Environment
6 evidence2 controls
CC1.2
Board independence and oversight of internal control
Control Environment
3 evidence1 control
CC1.3
Organizational structure, reporting lines, and authority
Control Environment
3 evidence1 control
CC1.4
Commitment to attract, develop, and retain competent individuals
Control Environment
6 evidence2 controls
CC1.5
Accountability for internal control responsibilities
Control Environment
3 evidence1 control
CC2.1
Obtains or generates and uses relevant quality information
Communication and Information
3 evidence1 control
CC2.2
Internal communication of information to support internal control
Communication and Information
6 evidence2 controls
CC2.3
External communication regarding matters affecting internal control
Communication and Information
4 evidence1 control
CC3.1
Specifies objectives with sufficient clarity
Risk Assessment
3 evidence1 control
CC3.2
Identifies and analyzes risks to achievement of objectives
Risk Assessment
3 evidence1 control
CC3.3
Considers potential for fraud in assessing risks
Risk Assessment
3 evidence1 control
CC3.4
Identifies and assesses significant changes
Risk Assessment
3 evidence1 control
CC4.1
Selects, develops, and performs ongoing and separate evaluations
Monitoring Activities
6 evidence2 controls
CC4.2
Evaluates and communicates internal control deficiencies
Monitoring Activities
3 evidence1 control
CC5.1
Selects and develops control activities that mitigate risks
Control Activities
3 evidence1 control
CC5.2
Selects and develops general controls over technology
Control Activities
6 evidence2 controls
CC5.3
Deploys control activities through policies and procedures
Control Activities
3 evidence1 control
CC6.1
Logical access security infrastructure
Logical and Physical Access Controls
11 evidence3 controls
CC6.2
Registration and authorization prior to issuing credentials
Logical and Physical Access Controls
6 evidence2 controls
CC6.3
Role-based access management
Logical and Physical Access Controls
6 evidence2 controls
CC6.4
Physical access restrictions
Logical and Physical Access Controls
3 evidence1 control
CC6.5Disposal and destruction of information assetsSOC 2Logical and Physical Access Controls
Official Requirement
The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's objectives.
When a hard drive, laptop, or server is retired, the data on it must be unrecoverable before you repurpose or dispose of it. Cloud snapshots and database backups have the same requirement when you delete them. This criterion also applies to customer data, when a customer ends their contract, their data must be handled according to your data retention and disposal policy.
These are typical controls and implementation steps. Your systems and environment may differ.
Typical Control Media sanitization and disposal procedure
Implementation Steps
For cloud storage, deletion of KMS-encrypted volumes effectively destroys the data if the key is also deleted, document this in your key management policy
Explicitly delete S3 bucket contents and the bucket itself (not just the access policy) when decommissioning a dataset
When terminating RDS instances, confirm final snapshot is deleted or that it is retained per policy with documented expiration
For customer data erasure requests, document the process and maintain records of erasure confirmation
Typical Control Media sanitization and disposal procedure
Evidence Artifacts
Data Retention and Disposal Policy showing data destruction requirements and timelines
KMS key deletion log or AWS CloudTrail event showing key scheduled for deletion when storage decommissioned
Customer data erasure request records with confirmation of deletion (if applicable)
📅Policy reviewed annually; deletion events documented per occurrence
Cross-framework mappings coming in v1.1
When we add ISO 42001 and ISO 27001, you'll see which controls map to this criterion.
ISO
ISO 42001
AI Management Systems
ISO
ISO 27001
Information Security
Mapping data will appear here automatically when the frameworks are published.
CC6.6
Controls against threats from outside system boundaries
Logical and Physical Access Controls
8 evidence2 controls
CC6.7
Restricts transmission and movement of information
Logical and Physical Access Controls
7 evidence2 controls
CC6.8
Controls to prevent or detect unauthorized software
Logical and Physical Access Controls
6 evidence2 controls
CC7.1
Detection and monitoring for vulnerabilities
System Operations
8 evidence2 controls
CC7.2
Monitoring for anomalies and security events
System Operations
4 evidence1 control
CC7.3
Evaluation of security events as security incidents
System Operations
4 evidence1 control
CC7.4
Incident response program
System Operations
4 evidence1 control
CC7.5
Recovery from security incidents
System Operations
4 evidence1 control
CC8.1
Authorized change management process
Change Management
8 evidence2 controls
CC9.1
Risk mitigation for business disruptions
Risk Mitigation
4 evidence1 control
CC9.2
Vendor and business partner risk management
Risk Mitigation
4 evidence1 control
Help us build what matters.
Vote for the next framework, subscribe for updates, and let us know if you'd contribute.
What should we add next?
Vote for the framework you need most.
0
ISO 42001
0
ISO 27001
0
CMMC
0
CPCSC
Stay Updated
Get notified when new frameworks and features are added.
On-premises implementation and evidence
Media sanitization and disposal procedure
Implementation steps
Wipe decommissioned drives with NIST 800-88-compliant methods: Secure Erase for SSDs, DoD 7-pass wipe for HDDs, or physical destruction for drives that cannot be sanitized
Maintain a media destruction log: asset tag, drive serial number, destruction method, date, person who performed it
For drives being physically destroyed, use a certified e-waste vendor who provides a destruction certificate
Laptop retirement must include drive wipe verification, BitLocker encryption alone does not satisfy disposal if keys were escrowed
Tools / systems
DBAN / Eraser (HDD wipe)
Manufacturer Secure Erase (SSD)
Blancco (commercial wipe + certificate)
Certified e-waste destruction vendor
Evidence artifacts
Media destruction log listing asset tag, serial number, destruction method, date, and performer for all retired drives in the audit period
Certificate of destruction from certified vendor (if physical destruction used)
Screenshot or output of Secure Erase / wipe tool confirming completion for sampled devices
Evidence frequency: Per decommission event; log maintained continuously; auditors will sample from destruction log