AICPA Trust Services Criteria — CC6.5
The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's objectives.
This is the criterion actually on point for asset disposal, and it sits in the Common Criteria — meaning it is in scope for every SOC 2 engagement, because Security is mandatory. Vendors more often cite the Confidentiality category, which is optional and which many reports do not elect at all.