KSI-SVC-RUD — Removing Unwanted Data

Official CR26 Key Security Indicator in the Service Configuration family (KSI-SVC). The statement below is verbatim from the catalog.

Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.

Official requirement

Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage.

Assessment considerations

Official related SP 800-53 controls: SI-12 (03), SI-18 (04).

Static HTML reference: scm.cc/ksi/ksi-svc-rud/. Interactive view: KSI Explorer (in progress).

Related hub pages

Primary sources

Last verified 2026-09-27. FedRAMP.gov is authoritative.

Explore the knowledge hub