Question

Difficulty: MediumThird-Party Risk Management and Supply Chain Oversight

An organization is ending its contract with a third-party cloud service vendor that hosted proprietary customer datasets. To satisfy data privacy compliance mandates and prevent unauthorized data disclosure, the security team must verify that all organizational data, including backups and shadow copies stored on the vendor's storage infrastructure, has been permanently removed and sanitized. Which of the following artifacts should the organization require from the vendor to validate that this requirement was completed?

  1. Certificate of DestructionAnswer
  2. B
    Service Level Agreement (SLA)
  3. C
    Business Impact Analysis (BIA)
  4. D
    Interconnection Security Agreement (ISA)

Answer

The organization should require a Certificate of Destruction from the vendor.
A Certificate of Destruction is a formal document provided by a vendor certifying that specific data, files, or physical media have been rendered unrecoverable using approved sanitization or destruction methods. During third-party vendor offboarding, obtaining this document is essential for confirming compliance with data governance and privacy policies.

Step-by-Step Solution

1
Identify the objective of vendor offboarding and data decommissioning
The objective is to obtain verifiable proof that all proprietary customer data and residual backups have been permanently sanitized by the third party.
Offboarding procedures require formal documentation ensuring vendor compliance with data retention and destruction policies.
2
Evaluate the function of third-party governance documents and compliance artifacts
Operational contracts (SLAs), network connectivity agreements (ISAs), and risk management analyses (BIAs) govern active operations or planning, whereas a Certificate of Destruction documents completed media/data sanitization.
Verifiable attestation requires an explicit confirmation artifact generated upon completing the data purge.
3
Select the appropriate artifact that fulfills the compliance validation requirement
A Certificate of Destruction officially confirms the method, date, and scope of data destruction.
This document ensures legal accountability and compliance with data privacy regulations.

Key Concept

Third-Party Vendor Offboarding and Data Destruction Attestation
Rate this question