NIST SP 800-53 r4 Privacy Control DM-2: Data Retention and Disposal, v4

Profile of requirements corresponding to NIST Special Publication 800-53 r4, Privacy Control DM-2: Data Retention and Disposal.
Identifier https://artifacts.trustmarkinitiative.org/lib/tips/nist-sp-800-53-r4-privacy-control-dm-2_-data-retention-and-disposal/4/
Publication Date 2021-04-26
Issuing Organization
No Responder help@trustmarkinitiative.org 555-555-5555 No Mailing Address
Keywords 800-53, Data Minimization, Data Retention, Disposal, NIST, Privacy, Retention
Legal Notice This document and the information contained herein is provided on an "AS IS" basis, and the Georgia Tech Research Institute disclaims all warranties, express or implied, including but not limited to any warranty that the use of the information herein will not infringe any rights or any implied warranties or merchantability or fitness for a particular purpose. In addition, the Georgia Tech Research Institute disclaims legal liability for any loss incurred as a result of the use or reliance on the document or the information contained herein.
Loading...

Trust Expression:

TD_ref1 and TD_ref2 and TD_ref3 and TD_ref4 and TD_ref5

References (5)

 TD  Privacy - Data Retention and Disposal - Secure Disposal of PII, v1.0
Description Defines conformance and assessment criteria for verifying that an organization disposes of, destroys, and/or erases PII, regardless of the method of storage in a manner that prevents loss, theft, misuse, or unauthorized access.
ID TD_ref1
Provider Reference
 TD  Privacy - Data Retention and Disposal - Secure Anonymization of PII, v1.0
Description Defines conformance and assessment criteria for verifying that an organization anonymizes the PII, regardless of the method of storage in a manner that prevents loss, theft, misuse, or unauthorized access.
ID TD_ref2
Provider Reference
 TD  Privacy - Data Retention and Disposal - NARA-Approved Record Retention Schedule, v1.0
Description Defines conformance and assessment criteria for verifying that an organization disposes of, destroys, erases, and/or anonymizes the PII, regardless of the method of storage, in accordance with a NARA-approved record retention schedule.
ID TD_ref3
Provider Reference
 TD  Privacy - Data Retention and Disposal - Retention of Collected PII, v1.0
Description Defines conformance and assessment criteria for verifying that an organization retains each collection of personally identifiable information (PII) for organization-defined time period to fulfill the purpose(s) identified in the notice or as required by law.
ID TD_ref4
Provider Reference
 TD  Privacy - Data Retention and Disposal - Secure Disposal Techniques, v1.0
Description Defines conformance and assessment criteria for verifying that an organization uses organization-defined techniques or methods to ensure secure deletion or destruction of PII (including originals, copies, and archived records).
ID TD_ref5
Provider Reference

Sources (1)

SP800-53R4 NIST Special Publication 800-53 Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, National Institute of Standards and Technology, April 2013 (Includes updates as of 01-15-2014). Available at http://dx.doi.org/10.6028/NIST.SP.800-53r4.
Also available as XML or JSON