CC6.5: Disposal of physical assets
When laptops, drives or other equipment leave the company's control, the data on them is wiped or destroyed first, and the disposal is recorded.
Category: Security (common criteria, required in every SOC 2 report) · Series: CC6 (Logical and physical access controls) · TSC 2017 (2022 points of focus)
That summary is Policyseed’s own paraphrase, written to be read next to the policy sections below. The authoritative wording is the AICPA’s Trust Services Criteria, which the CPA firm tests your controls against during the examination.
Policies that address CC6.5
The Policyseed crosswalk points CC6.5 at 3 policies. Each link opens the full sample text at the section an auditor would read. Section 4 holds the statements management commits to; section 5 holds the procedures that produce evidence.
- P05 Asset Management Policy, section 5 (Procedures). Owner: IT/Operations Lead.
- P07 Data Retention and Disposal Policy, section 5 (Procedures). Owner: Security Owner.
- P21 Physical and Remote Work Security Policy, section 5 (Procedures). Owner: IT/Operations Lead.
Evidence examples for CC6.5
Artifacts a company of 5 to 200 people can realistically produce. The Audit Kit’s evidence checklist lists them per policy with an owner column so each one has a name against it before the examination.
- MDM remote-wipe confirmation for laptops returned by leavers in the period
- Asset inventory entries marked disposed with the wipe date and method
- Certificate of destruction from the recycling or ITAD vendor, where used
Related criteria in CC6 (Logical and physical access controls)
- CC6.1: Logical access security
- CC6.2: User registration and deprovisioning
- CC6.3: Role-based access and least privilege
- CC6.4: Physical access
- CC6.6: Protection from external threats
- CC6.7: Data in transit and on removable media
- CC6.8: Malicious software
Previous: CC6.4 Physical access. Next: CC6.6 Protection from external threats. All 38 criteria are listed on the template index.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.