Regulatory Compliance
Information security and IT asset disposition are typically governed by best practices. In many cases, there are also government agencies with specific laws and regulations that dictate the proper sanitization and disposal of end-of-life media, ensuring there are adequate measures in place to safeguard information. SEM’ solutions are specifically designed and manufactured to comply with the most frequently cited regulatory requirements, and we have listed herein the devices that meet each compliance standard. This list is by no means exhaustive, and SEM encourages best practice processes and procedures when handling end-of-life media.
Securities & Exchange Comission
SOX speaks to retention of documents and unlawful destruction of records, proper disposal of consumer information is per the guidelines of the FDIC
US Dept of Health and Human Services
HIPAA: Disposal of Protected Health Information/Retention is governed by state law
PCI Security Standards Council
Destruction of media containing cardholder data
Office of the Privacy Commissioner of Canada
This is a Canadian law–it’s not as sweeping as the federal and state laws in the US governing the same
Federal Trade Commission
Fair and Accurate Credit Transactions Act: ties in with GLBA but added the Disposal Rule effective June 1, 2005
Department of Homeland Security
Disposal of devices safely