NIST 800-53 Rev 5

424 controls available

SR-12lowmoderatehigh

Component Disposal

Supply Chain Risk Management

Control Statement

Dispose of {{ insert: param, sr-12_odp.01 }} using the following techniques and methods: {{ insert: param, sr-12_odp.02 }}.

Discussion

Data, documentation, tools, or system components can be disposed of at any time during the system development life cycle (not only in the disposal or retirement phase of the life cycle). For example, disposal can occur during research and development, design, prototyping, or operations/maintenance and include methods such as disk cleaning, removal of cryptographic keys, partial reuse of components. Opportunities for compromise during disposal affect physical and logical data, including system documentation in paper-based or digital files; shipping and delivery documentation; memory sticks with software code; or complete routers or servers that include permanent media, which contain sensitive or proprietary information. Additionally, proper disposal of system components helps to prevent such components from entering the gray market.

Framework
NIST SP 800-53 Rev 5
Family
Supply Chain Risk Management
Baselines
low, moderate, high

Related Frameworks

4 paths across 2 frameworks
SCF1 mapping
AST-09Secure Disposal, Destruction or Re-Use of Equipment
0.50
  • Secure Controls Framework · 2026.2 · scf_strm · related
CCI3 mappings
CCI-005144
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-005145
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI-005146
1.00
  • DISA · 2025-01-23 · disa_cci_list · equivalent

Related STIGs

No STIGs in the current catalog reference any CCI mapped to this control.