Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.10

Information Deletion: A Practical Implementation Guide

Delete information when it is no longer required and verify deletion across systems, copies and suppliers.

This control concerns deleting information stored in systems, devices or other media when no longer required.

Practical interpretation: Deleting a record in an application may leave replicas, backups, exports, caches and supplier copies. Deletion must follow retention, legal hold and technical feasibility.

What should the control achieve?

  • Deletion triggers and responsibilities are defined.
  • Methods match technology and sensitivity.
  • Dependencies and third parties are included.
  • Completion is evidenced and exceptions are managed.

Step-by-step implementation

1

Map information locations

Identify primary stores, replicas, archives, backups, endpoints and processors.

2

Define triggers

Use retention expiry, contract end, rights request, purpose completion or asset disposal.

3

Select deletion methods

Apply application deletion, cryptographic erase, sanitization or destruction.

4

Coordinate dependencies

Handle indexes, caches, analytics, exports and downstream systems.

5

Control backups

Define expiry and protection where selective deletion is impractical.

6

Verify and evidence

Use logs, sampling, supplier confirmation and reconciliation.

What this could look like in practice

Customer accounts are deleted through a workflow that removes production records, search indexes and file objects, notifies subprocessors and lets encrypted backups expire under a documented schedule.

ActivityPractical implementationEvidence
Retention expiryAutomated job deletes eligible records.Deletion log
Customer requestVerified workflow searches all scoped systems.Case record
Supplier copyProcessor confirms deletion contractually.Certificate
BackupData remains protected until scheduled expiry.Backup policy

Implementation evidence

  • Deletion policy
  • Data-location map
  • Retention triggers
  • Deletion workflows
  • Job logs
  • Supplier confirmations
  • Backup treatment
  • Verification samples

Useful metrics

  • Deletion jobs completed
  • Records past retention
  • Supplier confirmations overdue
  • Deletion failures

Common mistakes

  • Deleting only the visible application record.
  • Ignoring exports and shadow copies.
  • Deleting during legal hold.
  • Promising selective backup deletion without capability.
  • Keeping deletion logs that recreate sensitive content.

Questions an auditor may ask

  • What triggers deletion?
  • Which copies are included?
  • How are backups handled?
  • Show verified deletion across a supplier.
Implementation test: Select one deletion case and trace every known copy, technical action, exception and completion record.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.