← Inspection rules
SEC-012 / v1.1.0 / 2026-10-02
Inspect nonproduction and data retirement deadlines
Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.
Applicability
Applies to cloud or database environments holding customer data, identity documents, initial credentials, or test copies.
Where to look first
- Development, test, BI, and backup copies, including former-member and incomplete-applicant data.
- Owners, purpose, privileges, retention deadlines, and retirement or deletion records.
Inspection steps
- Compare inventory and runtime assets for obsolete environments and overdue data.
- Inspect the need for production data in tests, anonymization and minimization, exposure, and authentication.
- Inspect how retention and deletion apply to copies, restoration, search, and backups as well as the live database.
Remediation direction
- Retire unnecessary environments and minimize data under an owner-approved retention policy; deletion follows authority and recovery requirements.
- Require ownership, deadlines, and access restrictions at environment creation; detect overdue assets.
Evidence required for completion
- Revision-linked asset and retention inventory with scoped deletion or anonymization records.
- Evidence covering production copies, former members, incomplete applicants, and backups.
Limits and unverified scope
- This catalog does not determine legal or contractual retention requirements; do not delete required data without authority.
- Defined settings or deadlines alone do not prove deletion; absent execution evidence remains unverified.