BS EN 15713:2023
$198.66
Secure destruction of confidential and sensitive material. Code of practice
Published By | Publication Date | Number of Pages |
BSI | 2023 | 56 |
This document provides recommendations and requirements for the procedures, processes and performance monitoring to be implemented for the management and control of the physical destruction of confidential and sensitive material to ensure that such material is disposed of securely and safely. This document can be referenced by anyone who processes such material on behalf of others and covers the following scenarios: – on site – using mobile equipment at the location of use (destruction equipment is brought to the confidential or sensitive material); – off site – transport followed by destruction using equipment at a destruction facility (the confidential or sensitive material is brought to the destruction equipment, such as used at a dedicated external facility operated by a service provider); – use of equipment at the Data Controller’s location (confidential or sensitive material and destruction equipment co-located, such as a shredder in a building occupied by a client or clients). Destruction by erasure (e.g. crypto erasure, data overwriting, degaussing or other forms of magnetic/electronic erasure) is not covered in this document.
PDF Catalog
PDF Pages | PDF Title |
---|---|
2 | undefined |
9 | 1 Scope 2 Normative references |
10 | 3 Terms, definitions and abbreviations 3.1 Terms and definitions |
13 | 3.2 Abbreviations |
14 | 4 Protection class 4.1 General 4.2 Determination of the protection class |
15 | 5 Determination of security level 6 Increasing the security level |
16 | 7 Destruction equipment 7.1 General 7.2 Use of destruction equipment 7.3 Operating instructions |
17 | 7.4 Destruction outcome 7.5 Confirmation of destruction process and its completion 7.6 Maintenance and performance monitoring |
18 | 7.7 Frequency of destruction equipment assessment 7.8 Redundancy of destruction equipment |
19 | 8 Company destruction premises and service provider holding sites 8.1 General 8.2 Destruction premises and service provider holding site secure areas 8.3 Security |
20 | 9 Controlled access to secure areas 9.1 General |
21 | 9.2 Authorization for access to a secure area for company personnel 9.3 Accompanied access to a secure area for company personnel without appropriate training 9.4 Visitors and contractors (non-company personnel) access to secure area |
22 | 9.5 Controlled access to secure area procedure for visitors and contractors (non- company personnel) 9.6 Secure area access level requirements for visitors and contractors (non-company personnel) |
23 | 10 Contract 11 Record of process of collection through to destruction 11.1 General 11.2 Confidential and sensitive material transfer record |
24 | 11.3 Certificate of destruction |
25 | 12 Subcontracting 13 Company personnel 13.1 Non-disclosure agreement 13.2 Security clearance of personnel |
26 | 13.3 Training of personnel |
27 | 13.4 Control of company drivers 14 Collection and transport of confidential and sensitive material 14.1 General 14.2 Mobile shredding and collection vehicles |
28 | 14.3 On site service – additional measures 14.4 Security containers |
29 | 14.5 Security bags 15 Storage and retention of confidential and sensitive material at destruction facility 16 Business continuity planning and responding to security incidents 17 Retention of records |
30 | 18 Categories of confidential and sensitive material |
31 | 19 End product waste disposal 20 Supply chain 21 Information security |
32 | Annex A (normative)Destruction outcomes tables |
39 | Annex B (normative)Secure destruction process |