Accountability should sit with the organisation that owns the data, even when contractors handle the physical work. Security, facilities, records management, and operations must share a documented process, but one team should own the control end to end. That owner must ensure labeling, access restrictions, surveillance, and destruction verification all work together.
Ownership should follow the data, not the contractor
The accountable party is the organisation that owns the information, because destruction is a data protection control, not just a facilities task. Contractors can perform transport, storage, or shredding, but they should do so under a process owned by the data holder, with clear handoffs, approval points, and evidence requirements from collection through final disposal.
That distinction matters because physical handling can be outsourced while accountability cannot. If the organisation cannot show who authorised the destruction, who had custody at each stage, and how the media was verified as destroyed, the control has failed even if the contractor followed a checklist.
For sanitisation and destruction expectations, the most directly relevant baseline is NIST SP 800-88 Media Sanitization, which distinguishes clearing, purging, and physical destruction and helps define what “destroyed” should mean in practice.
Why cross-facility handling needs one control owner
When media moves between offices, vaults, archives, and third-party destruction sites, the risk is fragmentation. Security may control the data classification, facilities may control access to the room, records management may track retention, and operations may schedule the pickup, but none of those functions alone can guarantee end-to-end protection.
The right model is shared execution with single-threaded accountability. One owner should define the minimum controls for labeling, storage, escort, access restriction, surveillance, chain-of-custody records, and destruction confirmation, then verify that each site and contractor can actually meet them.
That is why a formal media handling standard and disposal workflow should be aligned with the organisation’s broader control set, including physical safeguards and contractor oversight. A useful supporting reference is ISO/IEC 27002:2022 Information Security Controls, which helps structure how physical, organisational, and technological controls fit together.
What good accountability looks like in practice
Accountability is credible only when it is documented, measurable, and auditable. The owner should be able to produce a retention decision, an approved destruction trigger, a chain-of-custody record, the contractor’s service terms, and a destruction certificate or equivalent evidence tied to the specific batch of media.
- What to verify: the same owner signs off on the process, the labels match the inventory, and the destruction evidence maps to the exact devices or media units collected.
- What to measure: exceptions, missing certificates, delayed destruction, unescorted access, and any media that cannot be reconciled from inventory to final disposal.
- What practitioners underestimate: a contractor can physically destroy media while the organisation still fails on governance if it cannot prove custody, approval, and completion.
Practitioner takeaway: treat destruction as an owned control with delegated execution, not a vendor activity that ends accountability. The organisation that owns the data should own the control, because only that owner can bind classification, custody, physical safeguards, and verification into one defensible process.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.1 — Cybersecurity Governance | Data destruction accountability is a governance ownership decision for the organisation. |
| PR.AC — Identity Management, Authentication, and Access Control | Secure disposal depends on controlling who can access media and destruction areas. | |
| PR.DS — Data Security | Media destruction is a data security control that protects information at rest and at disposal. | |
| Recommendation — Assign end-to-end ownership for media destruction to a named governance function. Restrict access to media storage and destruction points to authorised personnel only. Apply destruction methods that render the media unreadable before release or reuse. | ||
| CIS Controls v8 | 5.3 — Data Retention and Disposal | The question is fundamentally about approved retention and destruction of media containing data. |
| 6.8 — Audit Log Management | Destruction needs traceable evidence of custody, approval, and completion. | |
| Recommendation — Define retention and disposal rules and retain evidence of approved destruction. Log media handoffs and destruction events so disposal can be audited end to end. | ||
| NIST SP 800-63 | IAL1 — Identity Assurance Level 1 | If contractor personnel are authorised to handle media, their identity assurance affects access trust. |
| Recommendation — Verify worker identities and authorisations before granting access to sensitive media. | ||
Related resources from NHI Mgmt Group
- Who is accountable for post-quantum migration across partners and contractors?
- Who is accountable for CSRMC-aligned cyber risk management across DoD programs and contractors?
- Who is accountable for securing SaaS integrations that create blind spots across an organisation?
- Who is accountable for securing sovereign AI infrastructure across telecom, IoT, and datacenter environments?