{
    "Disclaimer": [
        "The information in this database is for general guidance and is not to be relied upon as professional advice.",
        "DSIT has tried to ensure that the information on this database is accurate and up to date. DSIT will not accept liability for any loss and/or damage or inconvenience arising as a consequence of any use of or the inability to use any information on this website. DSIT endeavours to provide a reliable service; DSIT does not guarantee that its service will be uninterrupted or error-free. DSIT shall not be responsible for claims brought by third parties arising from your use of this database.",
        "DSIT assumes no responsibility for the contents of linked websites. The inclusion of any link should not be taken as endorsement of any kind by DSIT of the linked website or any association with its operators. DSIT has no control over the availability of the linked pages."
    ],
    "Copyright": "The copyright of the original material remains that of the original authors and any usage of excerpts in the mapping is made under fair use. References to organisations do not imply endorsement by DSIT.",
    "Version": "1.0",
    "Data": {
        "CEN/CENELEC": {
            "prEN 40000-1-2: Cybersecurity requirements for products with digital elements - Part 1-2: Principles for cyber resilience": {
                "link": "https://genorma.com/en/standards/pren-40000-1-2",
                "requirements": [
                    {
                        "requirementID": "7.10.",
                        "requirementText": "Planning for secure decommissioning"
                    }
                ]
            }
        },
        "Cloud Security Alliance (CSA)": {
            "AI Controls Matrix": {
                "link": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix",
                "requirements": [
                    {
                        "requirementID": "DCS-01",
                        "requirementText": "Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure disposal of equipment used outside the organization's premises. If the equipment is not physically destroyed a data destruction procedure that renders recovery of information impossible must be applied. Review and update the policies and procedures at least annually, or upon significant changes."
                    },
                    {
                        "requirementID": "DCS-02",
                        "requirementText": "Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. The relocation or transfer request requires the written or cryptographically verifiable authorization. Review and update the policies and procedures at least annually, or upon significant changes."
                    },
                    {
                        "requirementID": "DSP-02",
                        "requirementText": "Apply industry accepted methods for the secure disposal of data from storage media such that data is not recoverable by any forensic means."
                    }
                ]
            }
        },
        "Cyber Security Council (UAE)": {
            "National Cyber Security Policy for Artificial Intelligence": {
                "link": "https://csc.gov.ae/documents/38662/0/National+Cyber+Security+Policy+for+Artificial+Intelligence_v1.1.pdf/4e02b32e-9f62-948d-4bc8-b580d596451b?t=1766994254544",
                "requirements": [
                    {
                        "requirementID": "3.2.1 Asset Management for AI/ML Systems - 5",
                        "requirementText": "The entity should have a process to decommission and securely dispose of AI/ML assets when they reach their end of life, ensuring that appropriate data is securely wiped and cannot be recovered."
                    }
                ]
            }
        },
        "ETSI": {
            "EN 304 223 - Securing Artificial Intelligence (SAI); Baseline Cyber Security Requirements for AI Models and Systems": {
                "link": "https://www.etsi.org/deliver/etsi_en/304200_304299/304223/02.01.01_60/en_304223v020101p.pdf",
                "requirements": [
                    {
                        "requirementID": "Provision 5.5.1-1",
                        "requirementText": "If a Developer or System Operator decides to transfer or share ownership of training data and/or a model to another entity they shall involve Data Custodians and securely dispose of these assets. This will protect AI against security issues that can transfer from one AI system instantiation to another."
                    },
                    {
                        "requirementID": "Provision 5.5.1-2",
                        "requirementText": "If a Developer or System Operators decides to decommission a model and/or system, they shall involve Data Custodians and securely delete applicable data and configuration details."
                    }
                ]
            },
            "TR 104 128 - Securing Artificial Intelligence (SAI); Guide to Cyber Security for AI Models and Systems": {
                "link": "https://www.etsi.org/deliver/etsi_tr/104100_104199/104128/01.01.01_60/tr_104128v010101p.pdf",
                "requirements": [
                    {
                        "requirementID": "Provision 5.5.1-1",
                        "requirementText": "\"If a Developer or System Operator decides to transfer or share ownership of training data and/or a model to another entity they shall involve Data Custodians and securely dispose of these assets. This will protect AI against security issues that can transfer from one AI system instantiation to another.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nImproper disposal or transfer can lead to unauthorized data recovery, risking breaches, IP loss, and non-compliance with data protection laws.\n\nExample Measures/Controls:\nDevelop and Implement a Secure Transfer and Disposal Policy with Data Custodian Oversight: Establish a comprehensive policy to govern the secure transfer and disposal of training data and models. Ensure that Data Custodians oversee all actions, confirming compliance with regulatory standards, protection of intellectual property, and adherence to organizational policies. This includes compliance with GDPR when involving personal data."
                    },
                    {
                        "requirementID": "Provision 5.5.1-2",
                        "requirementText": "\"If a Developer or System Operators decides to decommission a model and/or system, they shall involve Data Custodians and securely delete applicable data and configuration details.\" (ETSI TS 104 223 [i.1])\n\nRelated threats/risks:\nInsecure data deletion during decommissioning can lead to unauthorized access to residual data, increasing regulatory and security risks.\n\nExample Measures/Controls:\nImplement a Secure Data Deletion Policy with Data Custodian Oversight: Establish a policy for securely deleting data and models during decommissioning, specifying methods compliant with standards. Ensure Data Custodians validate all deletions to maintain regulatory compliance and traceability."
                    }
                ]
            }
        },
        "NCSC/NSA/CISA etc": {
            "AI Data Security\n": {
                "link": "https://media.defense.gov/2025/May/22/2003720601/-1/-1/0/CSI_AI_DATA_SECURITY.PDF",
                "requirements": [
                    {
                        "requirementID": "1.9 Delete Data Securely",
                        "requirementText": "Prior to repurposing or decommissioning any functional drives used for AI data storage and processing, erase them using a secure deletion method such as cryptographic erase, block erase, or data overwrite. Refer to NIST SP 800-88, “Guidelines for Media Sanitization,” [20] for guidance on appropriate deletion methods."
                    }
                ]
            }
        },
        "NIST": {
            "AI RMF 1.0": {
                "link": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
                "requirements": [
                    {
                        "requirementID": "GOVERN 1.7",
                        "requirementText": "Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization’s trustworthiness."
                    }
                ]
            }
        }
    }
}