← Inspection rules

SEC-012 / v1.1.0 / 2026-10-02

Inspect nonproduction and data retirement deadlines

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Applies to cloud or database environments holding customer data, identity documents, initial credentials, or test copies.

Where to look first

  • Development, test, BI, and backup copies, including former-member and incomplete-applicant data.
  • Owners, purpose, privileges, retention deadlines, and retirement or deletion records.

Inspection steps

  1. Compare inventory and runtime assets for obsolete environments and overdue data.
  2. Inspect the need for production data in tests, anonymization and minimization, exposure, and authentication.
  3. Inspect how retention and deletion apply to copies, restoration, search, and backups as well as the live database.

Remediation direction

  • Retire unnecessary environments and minimize data under an owner-approved retention policy; deletion follows authority and recovery requirements.
  • Require ownership, deadlines, and access restrictions at environment creation; detect overdue assets.

Evidence required for completion

  • Revision-linked asset and retention inventory with scoped deletion or anonymization records.
  • Evidence covering production copies, former members, incomplete applicants, and backups.

Limits and unverified scope

  • This catalog does not determine legal or contractual retention requirements; do not delete required data without authority.
  • Defined settings or deadlines alone do not prove deletion; absent execution evidence remains unverified.

Additional references