A.8.10
    Technological Controls

    Information deletion

    Information stored in information systems, devices or in any other storage media should be deleted when no longer required.

    Purpose

    To prevent unnecessary retention of information and reduce exposure to unauthorized disclosure.

    Implementation Guidance

    Define data retention policies

    Implement automated data deletion where possible

    Ensure secure deletion methods are used

    Document deletion activities

    Verify data has been completely deleted

    Recommended Tools

    ISO 27001 Services from the Directory

    These providers can help you implement A.8.10 and achieve ISO 27001 certification.

    By the team behind ISMS Directory

    Implementing A.8.10 for a client?

    ISMS Copilot drafts policies, evidence, and SoA wording for A.8.10 Information deletion. Built for compliance professionals.

    Try ISMS Copilot free