Decommissioning protections
Summary
The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data has been diminished, and is no longer required to meet objectives.
access controlasset disposalmedia sanitisation
Read the full official text: https://www.aicpa-cima.com/resources/download/2022-trust-services-criteria
← Criterion CC6.4
Physical access restriction
Criterion CC6.6 →
Boundary protection against external threats
Track SOC 2 criterion CC6.5 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial