Secure methods are used to permanently destroy data that is no longer needed
Sekit's Data retention and disposal policy, one of A.5.1's topic-specific policies, sets legal minimums for how long each data category is kept and how it is destroyed afterward.
An approved retention schedule stating how long each data category is kept and how it is securely destroyed supports this control by setting the timeline records must be protected before disposal, though it does not address falsification or access controls.
This policy control sets the retention schedule and secure destruction method for data, the disposal rule A.7.14 requires before equipment carrying that data leaves the company.
The retention and disposal policy facet sets how long each data category is kept and the secure method used to destroy it, the schedule A.8.10 requires.