SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.8.10Information deletion

Delete information that is no longer needed from systems, devices and services, to reduce exposure and meet retention and privacy obligations.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Data retention and disposal procedure
The rules on how long data is kept and how it is securely destroyed when no longer needed.
Data subject rights procedure
The procedure for people to exercise their rights over their data (access, correction, deletion) and how those requests are handled on time.
From the Sekit evidence catalog

In practice

Deletion often stays theoretical at SMEs: a retention schedule gets written for a policy binder, but old customer records, terminated-employee files, and decommissioned laptops keep sitting in storage past their legal minimum because nobody owns the disposal step. The gap widens with data subject requests, where finding every copy of one person's data across email, a CRM, and backups can take days without a system that can search and delete on command. A working control ties disposal to the retention schedule with a recurring job, uses wiping or cryptographic erasure that produces a verifiable log for every destroyed device, and gives someone dedicated time to track access, correction, and deletion requests to a deadline.

Common gaps

The retention schedule sets deadlines, but no recurring disposal job runs against it, so decommissioned drives and old records pile up past their limit.
There is no verifiable record of what was destroyed, when, or how, so an auditor cannot confirm disposal happened as claimed.
Data subject deletion requests are handled manually with no tracking, so the company cannot show one was completed within the required timeframe.

Questions your auditor will ask

How long is customer data kept before it is deleted?
According to the retention and disposal procedure, which sets a maximum retention period per data category and the legal minimums that apply.
How do you prove a device was securely wiped rather than thrown away?
The wiping tool produces a verifiable disposal log recording the device, the method used, and the date it was destroyed.
What happens when someone asks the company to delete their personal data?
The request is logged in the data subject rights procedure, and the system locates and deletes every copy within the committed timeframe.
Who is responsible for running scheduled disposals?
A named owner runs disposals against the retention schedule and logs paper, device, and digital-record destruction as each one completes.

Where regulation demands it

NIS2 12.5 requires secure deletion of assets when they are no longer needed, and ENS mp.info.1 sets equivalent handling requirements for personal data.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.8.10?”
Also via MCP, free with account