STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← All Controls

SR-12

Supply Chain Risk ManagementRev 5organization

Component Disposal

Baselines:LowModerateHigh

Control Statement

Dispose of [Assignment: data, documentation, tools, or system components] using the following techniques and methods: [Assignment: techniques and methods].

Supplemental Guidance

Data, documentation, tools, or system components can be disposed of at any time during the system development life cycle (not only in the disposal or retirement phase of the life cycle). For example, disposal can occur during research and development, design, prototyping, or operations/maintenance and include methods such as disk cleaning, removal of cryptographic keys, partial reuse of components. Opportunities for compromise during disposal affect physical and logical data, including system documentation in paper-based or digital files; shipping and delivery documentation; memory sticks with software code; or complete routers or servers that include permanent media, which contain sensitive or proprietary information. Additionally, proper disposal of system components helps to prevent such components from entering the gray market.

Related Controls (1)

MP-6

CCI Identifiers (3)

CCI-005144Dispose of organization-defined data, documentation, tools, or system components using the following techniques and methods.CCI-005145Defines the data, documentation, tools, or system components which are to be disposed of using organization-defined techniques and methods.CCI-005146Defines the techniques or methods used to dispose of organization-defined data, documentation, tools, or system components.

Linked STIG Checks (0)

No STIG checks reference this control.