Defensible disposal
Destroying information routinely under a documented, consistently applied retention schedule, so the organisation can show the destruction was normal business practice, not concealment.
Defensible disposal is getting rid of information at the end of its retention period in a way the organisation can later justify to a court, regulator or auditor. It rests on a documented data retention schedule, consistent application of that schedule, and records showing what was destroyed, when, how and on whose authority. The method should suit the media and the sensitivity of the data, using the clear, purge and destroy methods of NIST SP 800-88 (currently Rev. 2, 2025), with a certificate of destruction where a vendor carries out the work.
The opposite outcome is spoliation: destroying evidence relevant to litigation or an investigation that is under way or reasonably anticipated. What separates them is usually timing and consistency, not the deletion itself. A legal hold suspends disposal for the affected records, and a routine schedule does not excuse destroying data covered by a hold. Disposing of data selectively, or only after a dispute begins, tends to undermine the defence. Defensible disposal also supports storage limitation and reduces what a breach can expose.
Exam relevance: a scenario is likely to describe an organisation holding large volumes of old data, or deleting records shortly before a lawsuit. Candidates are expected to tie disposal to the schedule, to recognise that a legal hold overrides it, and to spot when deletion becomes spoliation.