SR-12: Component Disposal

SR-12 requires organizations to dispose of data, documentation, tools, and system components using defined techniques that prevent sensit...

Quick-reference card

FieldValue
Control IDSR-12
Control NameComponent Disposal
FrameworkNIST SP 800-53, Revision 5
Control FamilySupply Chain Risk Management
BaselinesLOW MODERATE HIGH
RelevanceOrganization (Third Party)
Risk SeverityMedium

What this control requires

SR-12 requires organizations to dispose of data, documentation, tools, and system components using defined techniques that prevent sensitive information from being recovered. This control addresses a gap that most security programs overlook: what happens to hardware, storage media, and proprietary documentation when they leave your operational environment.

In practice, this means you need documented disposal procedures that cover every stage of the system development life cycle, not just the retirement phase. Components can require disposal during research and development, prototyping, design, and ongoing maintenance. Each of these phases produces artifacts that carry risk if improperly handled, including memory sticks with software code, servers with permanent media, shipping documentation, and paper-based system records.

The “so what” behind SR-12 is straightforward. Without controlled disposal, discarded components become a source of data leakage and supply chain compromise. Disposed hardware that still contains cryptographic keys, configuration data, or proprietary software can be resold on gray markets, giving adversaries direct access to your security architecture. You’re not just managing waste; you’re closing a persistent information exposure path that persists long after a system is decommissioned.

Why it matters

Improper component disposal is one of the most underestimated vectors in supply chain risk management. Organizations invest heavily in perimeter defenses and access controls but rarely apply the same rigor to what leaves the environment. The result is a compliance blind spot that auditors increasingly flag during assessments.

Failure to implement SR-12 creates direct audit risk across all three baselines. Because this control appears in LOW, MODERATE, and HIGH baselines, assessors expect to see documented disposal procedures regardless of your system’s impact level. A missing or incomplete disposal policy can generate findings that cascade into your overall authorization decision.

Beyond the audit itself, inadequate disposal practices expose your organization to regulatory liability. If disposed components contain personally identifiable information, protected health information, or controlled unclassified information, you may trigger notification obligations under overlapping regulations. The compliance burden compounds quickly when a single disposal failure implicates multiple frameworks.

Disposed system components also represent a tangible supply chain threat. Servers, routers, and storage devices that retain sensitive data can enter secondary markets where they’re accessible to threat actors. For organizations that rely on vendor risk management programs, verifying disposal practices across the vendor ecosystem is a critical gap to close.

What attackers exploit

  • Residual data on decommissioned hardware where disk cleaning or cryptographic key removal wasn’t performed before disposal, giving access to credentials, configurations, and proprietary code
  • Gray market resale of improperly sanitized components such as routers and servers with permanent media that still contain network architecture details and access credentials
  • Discarded documentation and shipping records that reveal system topologies, vendor relationships, and procurement details useful for social engineering and third-party risk exploitation
  • Memory sticks and portable media disposed of without sanitization that contain software source code, encryption keys, or authentication tokens

How to implement

For your vendors

The most common failure mode with vendor component disposal isn’t that vendors lack disposal processes entirely; it’s that their processes don’t account for your data specifically. Vendors often follow internal sanitization procedures for their own assets but fail to apply equivalent controls to components that processed, stored, or transmitted your information.

Start your assessment by requesting the vendor’s formal disposal policy and verifying it addresses the full scope of SR-12. The policy should cover data, documentation, tools, and system components across all life cycle phases, not just end-of-life retirement.

Key questions for security questionnaires:

  • What disposal techniques and methods do you use for system components that process our data?
  • Do your disposal procedures cover all life cycle phases, including prototyping, development, and maintenance?
  • How do you handle cryptographic key destruction when disposing of systems that stored encrypted data on our behalf?
  • What records do you maintain to document component disposal, and can you provide disposal certificates upon request?
  • Do you use certified third-party disposal vendors, and if so, what certifications do they hold?

Evidence to request:

You should collect the vendor’s media disposal policy, documented disposal procedures that reference supply chain protection, and sample disposal records showing the techniques applied to specific components. Ask for documentation that identifies which system components were flagged for disposal and the methods used for each category. A vendor security review should include verification that these records are maintained consistently and aren’t produced only when a customer asks.

Red flags to watch for:

Watch for vendors who can produce a disposal policy but no corresponding disposal records. A policy without execution evidence suggests the procedures exist on paper only. Other warning signs include disposal procedures that reference only end-of-life scenarios, omitting earlier life cycle phases where prototyping hardware or development environments are routinely decommissioned without formal sanitization.

Verification beyond self-attestation:

Request disposal certificates from vendors that hold recognized disposal or recycling certifications. Cross-reference disposal records against the vendor’s asset inventory to confirm that components identified for disposal were processed as documented. If the vendor uses a third-party disposal service, verify that the subcontractor’s practices meet the same standards. Where feasible, include disposal procedure verification in your onsite or virtual assessment scope rather than relying on questionnaire responses alone.

Evidence examples

Evidence TypeExample Artifact
Supply chain risk management policy and planPolicy defining disposal requirements across all system development life cycle phases, including roles, responsibilities, and approved disposal methods
Disposal proceduresDocumented procedures addressing media sanitization techniques, cryptographic key destruction, partial component reuse, and physical destruction methods
Media disposal and protection policyPolicy specifying sanitization standards for different media types, including magnetic drives, solid-state storage, and removable media
Disposal recordsLogs documenting each disposal event with component identifiers, disposal technique applied, date, and responsible personnel
Component identification documentationInventory records identifying system components flagged for disposal, including hardware serial numbers, media types, and data classification
Disposal technique documentationRecords specifying which techniques and methods were employed for each category of system component, with verification signatures
System security planRelevant sections describing the organization’s approach to component disposal within the broader supply chain risk management strategy

Cross-framework mapping

No cross-framework mappings are currently configured for this control.

  • MP-06 — Media Sanitization. MP-06 establishes the specific sanitization techniques and standards that SR-12 relies on when disposing of media-bearing system components, making it the operational complement to SR-12’s broader disposal requirements.

Frequently asked questions

What is NIST SP 800-53 SR-12?

SR-12 is a supply chain risk management control under NIST SP 800-53 that requires organizations to dispose of data, documentation, tools, and system components using approved techniques and methods throughout the system development life cycle. The control applies across all three baselines (LOW, MODERATE, and HIGH) and addresses the risk that improperly disposed components could expose sensitive information or enter gray markets. Organizations must maintain disposal records that document which components were disposed of, when, and what sanitization methods were applied.

What happens if SR-12 is not implemented?

Without SR-12 implementation, your organization faces audit findings that can jeopardize your system’s authorization to operate, since the control is required at every baseline. Assessors will look for documented disposal procedures and corresponding disposal records as evidence of compliance. Gaps in your media disposal policy or missing documentation of disposal techniques create findings that are difficult to remediate retroactively, because you can’t prove proper disposal after the fact. The risk extends beyond audit outcomes, as disposed system components without proper sanitization can expose cryptographic keys, proprietary configurations, and sensitive data to unauthorized parties.

How do you audit SR-12?

Auditing SR-12 starts with verifying that the organization has documented disposal procedures that cover data, documentation, tools, and system components across all life cycle phases. Assessors then examine disposal records to confirm that identified components were processed using the specified techniques and methods outlined in the procedures. The audit also checks whether the supply chain risk management plan addresses disposal-specific risks and whether media disposal policies align with the sanitization requirements in MP-06. Evidence should demonstrate a consistent chain from component identification through disposal execution, not just a policy that exists in isolation.

How should vendors securely dispose of system components?

Vendors should follow documented disposal procedures that specify approved techniques for each category of system component, including disk cleaning, cryptographic key removal, degaussing, and physical destruction. These procedures must cover disposal events at every phase of the system development life cycle, from prototyping through decommissioning, not just during final retirement. Vendors should maintain detailed disposal records that identify each component, the method applied, and the date of disposal, and they should provide disposal certificates to their customers upon request. Working with certified disposal providers adds an additional layer of assurance that sanitization meets established standards.

Experience superior visibility and a simpler approach to cyber risk management