Skip to main content
Category: Technical Security Controls

Information Deletion Control (8.10)

Also known as: Annex A 8.10, Control 8.10, A.8.10 Information Deletion, ISO 27002 Control 8.10
Simply put

Information Deletion is an ISO 27001:2022 Annex A control that requires organizations to securely delete data held in systems, devices, and storage media once it is no longer needed. Its aim is to reduce the risk of unauthorized access to and unnecessary exposure of sensitive information. It also helps organizations meet legal, statutory, regulatory, and contractual obligations related to retaining and disposing of data.

Formal definition

Control 8.10 (Information Deletion) is a technological reference control listed in Annex A of ISO/IEC 27001:2022 and detailed in ISO/IEC 27002:2022. It requires that information stored in information systems, on devices, or on other storage media be deleted securely and permanently when it is no longer required, in order to prevent unauthorized access and unnecessary exposure of sensitive information and to support compliance with applicable legal, statutory, regulatory, and contractual requirements. As an Annex A control, its inclusion in a given ISMS is determined via the Statement of Applicability and informed by risk assessment rather than being universally mandatory; the specific deletion methods and retention parameters depend on organizational scope, data classification, and applicable obligations. This control applies only within the defined scope of the ISMS and does not, by itself, guarantee that data has been irrecoverably destroyed in all circumstances.

Why it matters

Information that is retained beyond its useful life represents an ongoing liability. Every additional copy of sensitive data held in systems, on devices, or on storage media expands the potential attack surface and increases the risk of unauthorized access and unnecessary exposure. Control 8.10 addresses this by requiring organizations to securely delete data once it is no longer required, reducing the volume of information an attacker, insider, or misconfigured system could expose.

Beyond security, timely and secure deletion supports compliance with legal, statutory, regulatory, and contractual obligations governing how long data may be kept and how it must be disposed of. Many retention regimes impose limits on how long certain categories of data may be held, and failure to delete data at the end of its retention period can create both regulatory exposure and evidentiary complications. Implementing this control helps align an organization's actual data-handling practices with its stated retention commitments.

As an Annex A reference control, 8.10 is included in an ISMS through the Statement of Applicability and informed by risk assessment rather than being universally mandatory. Its scope covers only the information environment defined within the ISMS, and by itself it does not guarantee that data has been irrecoverably destroyed in all circumstances. Organizations typically need to combine documented retention schedules, appropriate deletion methods, and verification to demonstrate the control is operating as intended.

Who it's relevant to

Compliance and GRC Managers
Those responsible for the Statement of Applicability and ISMS documentation need to determine whether Control 8.10 is applicable within their scope, justify that decision against risk assessment results, and ensure retention and disposal obligations from legal, statutory, regulatory, and contractual sources are reflected in organizational procedures.
Security Engineers and IT Operations
Teams that manage systems, devices, and storage media implement the deletion methods that satisfy this control. They select techniques appropriate to data classification and media type and ensure that data is securely deleted when it is no longer required, recognizing that secure deletion does not by itself guarantee irrecoverable destruction in every circumstance.
Auditors and Certification Bodies
Assessors reviewing an ISMS against ISO/IEC 27001:2022 examine whether Control 8.10, where included, is designed and operating to securely delete information no longer required. They evaluate retention schedules, disposal procedures, and evidence of deletion within the defined ISMS scope.
Data and Records Management Owners
Personnel accountable for retention schedules and data lifecycle policies help define when information is no longer required and how it must be disposed of, aligning deletion practices with applicable legal, statutory, regulatory, and contractual retention and disposal requirements.

Inside Information Deletion Control (8.10)

Annex A Reference Control (ISO/IEC 27001:2022)
Information Deletion is control 8.10 in the Annex A control set of the 2022 revision of ISO/IEC 27001, which restructured the previous 2013 edition into 93 controls organized across four themes. As an Annex A control, it is a reference control selected via the Statement of Applicability and informed by the organization's risk assessment, rather than a certifiable clause requirement (which reside in clauses 4 through 10).
Purpose and Scope
The control addresses the deletion of information stored in information systems, devices, or any other storage media when it is no longer required. Its intent is typically to reduce exposure of sensitive or personal data, limit retention beyond legitimate need, and support compliance with applicable legal, regulatory, and contractual retention and disposal obligations. The precise scope depends on the organization's data landscape and risk decisions.
Deletion Methods and Techniques
Implementation commonly considers appropriate deletion techniques according to the sensitivity and storage medium involved, which may include secure overwriting, cryptographic erasure, or physical destruction. The suitable method depends on scope and risk, and further detailed guidance is typically found in the companion guidance standard ISO/IEC 27002 rather than in the certifiable requirements of ISO/IEC 27001.
Relationship to Third-Party and Cloud Storage
Where information resides with external providers or cloud services, deletion arrangements typically need to be addressed through contractual terms and provider capabilities. Cloud-specific expectations may be informed by complementary standards such as ISO/IEC 27017 and ISO/IEC 27018, though the applicability of these depends on the environment and scope.
Records and Verification
Organizations often maintain evidence that deletion has occurred in accordance with defined requirements, such as logs or records of disposal, to demonstrate operation of the control. The extent of verification expected depends on the certification body's assessment and the organization's own risk-based decisions.

Common questions

Answers to the questions practitioners most commonly ask about Information Deletion Control (8.10).

Is Information Deletion (8.10) a mandatory control that every ISO 27001-certified organization must implement?
Not automatically. Annex A controls, including 8.10 in the ISO/IEC 27001:2022 revision, are reference controls selected via the Statement of Applicability and informed by risk assessment. An organization may justify excluding a given Annex A control if it is not applicable to its ISMS scope, provided the exclusion is documented and rationalized. The certifiable requirements themselves are in clauses 4 through 10, so whether 8.10 applies depends on your risk assessment and scope rather than being universally required.
Does implementing Information Deletion (8.10) for ISO 27001 mean my SOC 2 requirements around data disposal are also covered?
Not necessarily. SOC 2 is an attestation examination against the Trust Services Criteria, while ISO 27001 Annex A 8.10 is a reference control within a management system standard, and the two are structured differently. Mapping between the frameworks is possible but partial, and satisfying one does not automatically satisfy the other. Disposal-related expectations in a SOC 2 engagement depend on the criteria in scope and the auditor's assessment, so you would need to evaluate each framework's requirements independently rather than assuming equivalence.
How should an organization approach documenting information deletion under 8.10?
Documentation typically covers when information is deleted, the methods used, and the systems or media affected, aligned to retention decisions and applicable legal or contractual obligations. In most engagements, organizations maintain records that demonstrate deletion occurred as intended, since auditors and certification bodies generally look for evidence that the control operates as described. The specific form and depth of documentation depend on scope, risk assessment, and the expectations of the certification body.
What methods are commonly used to satisfy information deletion requirements?
Approaches typically include secure overwriting, cryptographic erasure, and physical destruction of media, with the chosen method often matching the sensitivity of the information and the medium involved. Cloud and third-party environments may rely on provider deletion mechanisms, which is why organizations frequently confirm how such deletion is performed. There is no single mandated method; the appropriate approach depends on scope, risk, and the systems in use.
How does information deletion interact with data retention obligations?
Deletion and retention are generally treated as complementary: retention rules define how long information must be kept, and deletion controls address removal once retention periods lapse or a business or legal basis no longer applies. In most implementations, organizations reconcile 8.10 with retention schedules to avoid deleting information that must be preserved or keeping information beyond its justified period. The balance between these depends on applicable legal, regulatory, and contractual requirements, which vary by organization.
How can an organization demonstrate that information deletion is operating effectively over time?
Evidence commonly includes logs or records of deletion activities, confirmations from systems or service providers, and periodic reviews that deletion aligns with retention and disposal decisions. For a SOC 2 Type II examination, which assesses operating effectiveness over a defined review period, this kind of ongoing evidence is typically relevant, whereas a Type I assesses design at a point in time. What constitutes sufficient evidence depends on the auditor, certification body, and the scope of the engagement.

Common misconceptions

Because Information Deletion (8.10) is listed in Annex A, it is mandatory for every ISO 27001 certification.
Annex A controls are reference controls selected through the Statement of Applicability and informed by risk assessment; they are not automatically required. An organization may justify the exclusion of a control where it is not applicable. The certifiable ISMS requirements are in clauses 4 through 10, not in Annex A itself.
Satisfying control 8.10 under ISO 27001 means the equivalent data disposal expectations under a SOC 2 examination are also met.
Mapping between ISO 27001 Annex A controls and the SOC 2 Trust Services Criteria is possible but only partial. Satisfying one framework does not automatically satisfy the other, and SOC 2 is a CPA attestation examination while ISO 27001 is a certification against a management system standard. Deletion-related expectations under each depend on scope and applicable criteria.
The 8.10 control number and its content are the same across all editions of the standard.
Control 8.10 as numbered exists in the 2022 revision, which reorganized the earlier 2013 edition (114 controls) into 93 controls across four themes. Control numbering and structure differ between editions, so the version should always be specified when citing this control.

Best practices

Document the treatment of Information Deletion (8.10) in the Statement of Applicability, recording whether it is included or excluded and the risk-based justification for that decision.
Define deletion methods appropriate to the sensitivity and storage medium involved, and consider consulting ISO/IEC 27002 for detailed implementation guidance since ISO/IEC 27001 does not prescribe specific techniques.
Address deletion of information held by external and cloud providers through contractual terms, and consider whether complementary standards such as ISO/IEC 27017 or ISO/IEC 27018 are relevant to your environment.
Retain records or logs demonstrating that deletion occurred in accordance with defined requirements, to support evidence of the control's operation during assessment.
Align deletion practices with applicable legal, regulatory, and contractual retention and disposal obligations rather than treating deletion timing as a single fixed rule.
Specify the ISO/IEC 27001 edition (for example, the 2022 revision) whenever referencing control 8.10 in internal documentation or audit correspondence, since numbering and structure vary by version.