Termination - Destruction of Sensitive Data, v1.0

Defines privacy requirements related to the destruction of sensitive information.

Assessment Step

1
Termination - Destruction Of Sensitive Data (Termination-DestructionOfSensitiveData)
Does the organization destroy any sensitive information in the event that the organization ceases to provide its service, or the user ceases to use the organization's service?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Information Typesrequired
ENUM_MULTI : Select the type(s) of sensitive information that apply.
  • PII
  • PHI
  • III
  • IIHI
  • Other

Conformance Criteria (1)

C-1
The organization destroys any sensitive data including personally identifiable information in the event that the organization ceases to provide its service, or the user ceases to use the organization's service.
Citation
FICAM-TFPAP
Section 3.2.5