A.8.10 Technological
Information deletion
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (14)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- MP-6mostlyaligns with — Both controls require organizations to apply approved sanitization techniques to storage media and verify that sensitive information is irretrievably removed when it is no longer needed.
- MP-6mostlycovers — A.8.10's deletion requirement (including sanitization for media to meet legal/regulatory needs) accounts for the bulk of MP-6's sanitization mandate before disposal/reuse, but leaves a residual on MP-6's explicit strength/integrity calibration to security categorization that A.8.10 does not directly address.
- AU-11partialaligns with — Both controls require retention of evidence—deletion logs or audit records—to demonstrate that information was disposed of in accordance with policy.
- CM-6partialaligns with — Both controls rely on automated configuration settings to enforce secure deletion according to retention schedules and classification rules.
- SA-9partialaligns with — Both controls require organizations to impose and verify deletion or sanitization obligations on external service providers that store organizational information.
- SI-18partialaligns with — Both controls emphasize the timely removal of information that is no longer required to reduce exposure risk and maintain data quality objectives.
- AU-11covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- SI-18covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (20)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-08mostlyaligns with — By mandating secure deletion at end-of-life for systems, services, and media, the control operationalizes the CSF requirement to manage assets throughout their full life cycle.
- PR.DS-01mostlyaligns with — The ISO control's requirement to apply secure deletion methods to data-at-rest when it is no longer needed directly supports the CSF outcome of protecting the confidentiality, integrity, and availability of stored data.
- GV.SC-05partialaligns with — The control's explicit inclusion of deletion requirements in third-party agreements and verification of cloud-provider deletion capabilities aligns with the CSF outcome of embedding cybersecurity requirements into supplier contracts.
- PR.PS-02partialaligns with — Secure removal of obsolete software, temporary files, and versions when they are no longer required contributes to the CSF outcome of maintaining or replacing software commensurate with risk.
- PR.PS-03partialaligns with — The control's guidance on degaussing or physically destroying storage media and hardware when disposing of equipment supports the CSF outcome of removing hardware commensurate with risk.
- PR.PS-04partialaligns with — Requiring logs or evidence of deletion actions provides the records that the CSF outcome expects to be generated and made available for continuous monitoring.
- GV.SC-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.AM-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.DS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-03implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-04implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (7)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V14.2.7mostlyaligns with — Both require that sensitive data be removed once it is no longer needed, enforcing automated or policy-driven deletion to limit exposure.
- V13.3.4partialaligns with — Requiring secrets and sensitive data to be expired and rotated according to documented schedules mirrors the ISO guidance on scheduled, policy-driven deletion of information.
- V14.2.4partialaligns with — The ISO control’s emphasis on documented retention rules and secure deletion methods directly supports the ASVS requirement to define and apply data-retention controls for sensitive information.
Related weaknesses / CWE (35)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-256nonemitigates — Requires secure deletion of sensitive information, indirectly reducing exposure of stored plaintext passwords.
- CWE-313nonemitigates — Deletion policies help remove sensitive cleartext files when no longer needed.
- CWE-314nonemitigates — Deletion policy reduces exposure window but does not address the initial cleartext storage decision.
- CWE-459noneprevents — Explicitly requires secure deletion of temporary or residual data, directly addressing incomplete cleanup.
- CWE-528nonemitigates — Secure deletion of core dumps reduces residual exposure, but does not prevent the initial unauthorized access.
- CWE-1272prevents — Explicit information-deletion requirements directly address uncleared sensitive data on state transitions.
- CWE-1301prevents — Mandates procedures for secure information deletion that would prevent incomplete hardware data removal.
- CWE-200prevents — By enforcing timely, verifiable removal of sensitive data from systems and storage media, the control reduces the window during which residual information can be accessed by unauthorized actors.
- CWE-212prevents — Explicit information-deletion control directly addresses improper removal of sensitive data.
- CWE-226prevents — Explicitly requires secure deletion of information before resources are reused or disposed.
- CWE-244prevents — Explicitly requires secure deletion of sensitive data, directly addressing improper heap clearing.
- CWE-312mitigates — Secure deletion of obsolete or temporary copies prevents sensitive data from remaining in cleartext on disk after its intended lifetime.
- CWE-522mitigates — Requiring cryptographic erasure or physical destruction of storage that held credentials limits the chance that recoverable copies of authentication material persist beyond their required retention period.
- CWE-524mitigates — Information deletion ensures sensitive data is removed from caches when no longer needed.
- CWE-532mitigates — Mandating deletion of temporary files and logs that may contain sensitive information prevents those artifacts from remaining accessible after the data is no longer needed.
- CWE-538mitigates — The control’s requirement to remove or securely destroy information stored in externally accessible locations reduces the risk of sensitive data being left in files or directories that external parties can reach.
- CWE-539mitigates — Information deletion policies can mandate removal or encryption of sensitive cookie data.
- CWE-664prevents — Information deletion control ensures proper release and sanitization at end of life.
- CWE-921mitigates — Deletion reduces exposure but does not address the lack of access control on existing storage.
Mitigated MITRE ATT&CK techniques (143)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005prevents — A.8.10 requires timely secure deletion of sensitive information no longer needed (via overwriting, crypto erase, automation per retention policy, etc.), which stops that data from existing on local systems for an adversary to search and collect under T1005; it is only a slice because the technique also reaches data still required by business rules, data created after last deletion cycle, and non-sensitive files.
- T1052prevents — A.8.10 mandates secure deletion (overwriting, cryptographic erasure, approved tools, automated policies, physical destruction) of sensitive information no longer required, which stops data from being available on removable media for an adversary to copy and exfiltrate via T1052; this is a genuine but minority slice because the control only reaches data already present and scheduled for deletion, not the broader set of live sensitive data an adversary can still access and copy to physical media before deletion policies apply.
- T1114.001prevents — A.8.10 mandates timely secure deletion of information no longer required (including obsolete copies, temp files, and local storage via approved methods), which stops many .ost/.pst email artifacts from persisting as collectible targets; it does not reach live email data still required for business or email that is never deleted.
- T1213prevents — A.8.10 requires timely secure deletion of unneeded sensitive information (including in repositories, cloud stores, and third-party services), which directly stops the data from remaining available to be mined or externally shared as described in T1213; it is only partial because the control is scoped to data past its retention period or no longer required, leaving repositories that hold currently-needed sensitive data (or are misconfigured for broad access while still required) untouched.
- T1213.001prevents — A.8.10 requires timely secure deletion of information no longer required (including in cloud/SaaS services via agreements, automation, and approved methods), which stops sensitive data from remaining available in a Confluence repository for an adversary to mine; this is only a slice because the control depends on correct retention policy, classification, and implementation choices that do not guarantee removal of all such data before it can be targeted.
- T1213.002prevents — A.8.10 requires timely, secure deletion of information no longer required (including obsolete copies, temp files, and SharePoint-stored data per retention policy), which stops the repository from continuing to serve as a viable mining source for the listed sensitive items; it is only partial because the control is scoped to data past its retention period or marked for deletion and does not stop an adversary from mining still-valid, in-scope SharePoint content before any deletion trigger.
- T1486recovers — A.8.10 requires automated, policy-driven secure deletion (overwriting, cryptographic erasure, certified disposal) of data no longer required, which directly enables recovery of availability for data that would otherwise be rendered permanently inaccessible by ransomware encryption when the key is withheld.
- T1490recovers — A.8.10 requires configuring automated secure deletion per retention policy, deleting obsolete copies/backups, using approved disposal, and verifying cloud provider deletion — directly enabling recovery of retained sensitive information after an adversary has deleted recovery artifacts (e.g. shadow copies, snapshots, prior versions).
- T1530prevents — A.8.10 requires timely, secure deletion (overwriting, crypto erase, automated per retention policy) of data no longer needed in cloud storage, which stops the data from being present for T1530 to access; it is only a slice because the technique also succeeds against live, still-required data protected only by access controls that this clause does not address.
- T1552prevents — Securely deleting credentials and other sensitive files when they are no longer needed reduces the chance an adversary will find unsecured credentials in files or other locations.
- T1552.001prevents — A.8.10 requires timely secure deletion of unneeded sensitive information (including credential-bearing files, configs, backups, temp files, and logs), which stops many instances of insecure credential storage from persisting and being discoverable; it does not prevent users or processes from creating them in the first place or address all cases (e.g., live credentials in active configs or source that are still required).
- T1552.003prevents — A.8.10 requires configuring systems to securely destroy information (including obsolete files and history) when no longer required per retention policy, which can delete ~/.bash_history, ConsoleHost_history.txt and similar before an adversary searches them; this is only a slice because the control is scoped to sensitive information under retention rules rather than universally clearing all command history on every logout or session.
- T1552.004prevents — A.8.10 requires secure deletion (overwriting, cryptographic erasure, approved tools, automated policies) of information no longer required, which stops private keys from remaining on disk as searchable artifacts; this directly prevents the discovery step of T1552.004 for keys that have reached end-of-life, but leaves live keys still in use (and many in-transit or memory-resident cases) untouched.
- T1555.003prevents — A.8.10 requires deleting credentials (and other sensitive data) when no longer required via secure methods, which stops browser-stored credentials from persisting as an available target for T1555.003; this is only a slice because the technique also covers in-memory extraction and credentials that remain required/valid.
- T1561.002recovers — A.8.10 requires secure deletion of unneeded sensitive information (including via approved methods, automation, and records) and explicitly ties this to restoring availability after a leakage or destruction event via official records and physical destruction controls (7.14); this recovers from the post-wipe unbootable state for data that was intentionally retained elsewhere, with the named remainder being systems where the wiped structures held the only copy.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A04mitigates — A.8.10's deletion (overwriting, crypto erase, media destruction) removes plaintext copies at end-of-life, bounding the consequence of any remaining weak/absent crypto on the data that was supposed to be deleted.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.