Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Who should be accountable for securing media marked…
Cyber Security

Who should be accountable for securing media marked for destruction across facilities and contractors?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

Accountability should sit with the organisation that owns the data, even when contractors handle the physical work. Security, facilities, records management, and operations must share a documented process, but one team should own the control end to end. That owner must ensure labeling, access restrictions, surveillance, and destruction verification all work together.

Ownership should follow the data, not the contractor

The accountable party is the organisation that owns the information, because destruction is a data protection control, not just a facilities task. Contractors can perform transport, storage, or shredding, but they should do so under a process owned by the data holder, with clear handoffs, approval points, and evidence requirements from collection through final disposal.

That distinction matters because physical handling can be outsourced while accountability cannot. If the organisation cannot show who authorised the destruction, who had custody at each stage, and how the media was verified as destroyed, the control has failed even if the contractor followed a checklist.

For sanitisation and destruction expectations, the most directly relevant baseline is NIST SP 800-88 Media Sanitization, which distinguishes clearing, purging, and physical destruction and helps define what “destroyed” should mean in practice.

Why cross-facility handling needs one control owner

When media moves between offices, vaults, archives, and third-party destruction sites, the risk is fragmentation. Security may control the data classification, facilities may control access to the room, records management may track retention, and operations may schedule the pickup, but none of those functions alone can guarantee end-to-end protection.

The right model is shared execution with single-threaded accountability. One owner should define the minimum controls for labeling, storage, escort, access restriction, surveillance, chain-of-custody records, and destruction confirmation, then verify that each site and contractor can actually meet them.

That is why a formal media handling standard and disposal workflow should be aligned with the organisation’s broader control set, including physical safeguards and contractor oversight. A useful supporting reference is ISO/IEC 27002:2022 Information Security Controls, which helps structure how physical, organisational, and technological controls fit together.

What good accountability looks like in practice

Accountability is credible only when it is documented, measurable, and auditable. The owner should be able to produce a retention decision, an approved destruction trigger, a chain-of-custody record, the contractor’s service terms, and a destruction certificate or equivalent evidence tied to the specific batch of media.

  • What to verify: the same owner signs off on the process, the labels match the inventory, and the destruction evidence maps to the exact devices or media units collected.
  • What to measure: exceptions, missing certificates, delayed destruction, unescorted access, and any media that cannot be reconciled from inventory to final disposal.
  • What practitioners underestimate: a contractor can physically destroy media while the organisation still fails on governance if it cannot prove custody, approval, and completion.

Practitioner takeaway: treat destruction as an owned control with delegated execution, not a vendor activity that ends accountability. The organisation that owns the data should own the control, because only that owner can bind classification, custody, physical safeguards, and verification into one defensible process.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.1 — Cybersecurity GovernanceData destruction accountability is a governance ownership decision for the organisation.
PR.AC — Identity Management, Authentication, and Access ControlSecure disposal depends on controlling who can access media and destruction areas.
PR.DS — Data SecurityMedia destruction is a data security control that protects information at rest and at disposal.
Recommendation — Assign end-to-end ownership for media destruction to a named governance function. Restrict access to media storage and destruction points to authorised personnel only. Apply destruction methods that render the media unreadable before release or reuse.
CIS Controls v85.3 — Data Retention and DisposalThe question is fundamentally about approved retention and destruction of media containing data.
6.8 — Audit Log ManagementDestruction needs traceable evidence of custody, approval, and completion.
Recommendation — Define retention and disposal rules and retain evidence of approved destruction. Log media handoffs and destruction events so disposal can be audited end to end.
NIST SP 800-63IAL1 — Identity Assurance Level 1If contractor personnel are authorised to handle media, their identity assurance affects access trust.
Recommendation — Verify worker identities and authorisations before granting access to sensitive media.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org