One of the most important steps to take in the lifecycle of business technology is proper disposal of data when devices are retired. Many times, users simply move their data over to their new device and then trash the old one. However smart adversaries can easily get their hands on the old device and remove the storage devices to gain easy access to the data. This can put large amounts of critical company data at risk.
The process of disposing of data is really broken down into a few different steps. The differences between these steps are important to understand. The first step is to assess the retired devices to understand what kind of data they contain. In a business environment, it is likely that all company devices contain data that is important to the company’s security in one way or another. Before the storage devices can be sanitized and destroyed, the company data needs to be classified and archived in a secure location for future use. The process of data retention and archiving has its own separate documentation.
Once appropriate pieces of company data have been extracted and archived from a device, it is time to move onto the process of sanitizing the data off of the storage media. Media sanitization is a process that renders access to target data on the media infeasible for a given level of effort. The goal here is to remove all sensitive data from the storage device. Once the storage media has been sanitized, a decision must be made as to whether the storage media should be preserved for future use, or completely destroyed, never to be used again. Many businesses opt to preserve storage devices to be rotated into the environment for future use. For example, a 1 terabyte hard disk drive may be perfectly healthy for use in the storage pool of a new on-premises server, or for use as a hot spare backup.
In other cases, businesses may decide that storage media serves no further purpose to the organization and can be trashed. However, even after sanitization, many storage devices still run the risk of containing residual data that is left over on the drive. This has a much higher probability than one may think. This is where the next step, data destruction comes into place. Data destruction is the process of destroying data stored on tapes, hard disks and other forms of electronic media so that it's completely unreadable.
In many cases, media sanitization and data destruction are used interchangeably. However, be aware of the key difference: media sanitization refers to the basic act of removing data from storage media, while data destruction refers to the final act of destroying storage media once it serves no further purpose to the organization. Before jumping right from sanitization to destruction, organizations should consider whether or not the storage media might be retained for possible use in other aspects of the environment.
Businesses should have a clear policy in place governing the process of sanitizing and destroying data at the end of a device’s lifespan. This policy should be accompanied by clear procedures that further break down the steps taken to perform sanitization and destruction of data. Businesses need to decide which methods to use for sanitization and destruction of data. There are several different options, each with a more secure level of assurance for complete removal of data.
Media sanitization methods fall under one of two categories:
- Logical: Software tools are used to replace data on storage media and ultimately deny access to it. Logical techniques are used when the organization wishes to preserve the storage media for future use.
- Physical: Real world physical measures are taken to render the storage media completely unusable. This technique is typically what we mean when we refer to “data destruction”.
Within the two categories are various methods for sanitizing and/or destroying data.
- Clear: this method involves removing data in user addressable storage locations to prevent against basic recovery techniques. Clearing is usually done by overwriting data with new values, or by using built-in firmware to reset the storage media to a factory state. Data that has been cleared still runs the risk of being recovered by advanced methods. Clearing is generally the least secure method of sanitization, and should only be used on storage devices that are going to be saved by the organization for use in the same department.
- Purge: this method involves using advanced techniques to make data recovery infeasible while still leaving the storage media potentially re-usable. Methods of purging data may include overwriting, block erase, and cryptographic erase. Purging storage media is more secure than simply clearing it, but has a higher risk of rendering the storage media unusable. Cryptographic erase is becoming of particular interest, as it provides a way to purge virtual storage used in cloud resources, which most other sanitization methods cannot account for. Cryptographic erase is a method of sanitization in which the media encryption key (MEK) for the encrypted target data is sanitized, making recovery of the decrypted Target Data infeasible. Think of it as throwing away the key forever to data that is locked in a prison cell.
- Destroy: If there is no reason for the storage media to be preserved in a usable state, a destruction method should be used. Destroying media involves using physical means to irreversibly alter the form and usability of the storage device. Techniques for destruction include disintegrating, incinerating, melting, pulverizing, and shredding. A particular method called degaussing involves using a magnetic field to ruin the magnetic platters on a hard drive. Degaussing renders the drive unusable, but leaves its physical properties intact. Thus, it falls somewhere between purging and destroying. Machinery for degaussing can be quite expensive, putting it out of scope for many small businesses. Degaussing may also be unjustifiable financially, as it works only on hard disk drives, not solid state drives, which are becoming dominant in the information technology market.
Media sanitization and data destruction policies should make sure to emphasize that storage media should be tested after initial sanitization to ensure that the operations worked. Without validation, partially sanitized or completely intact data could be thrown out under the assumption that full sanitization was performed.
Businesses should provide logs to be filled out for the destruction of each individual storage device. The logs should account for the individual performing the sanitization/destruction, the method used, the date and time of the activity, the initial result, verification of a test, and a final signature confirming completion.
Once data has been fully sanitized and destroyed, the storage media should be moved to e-waste.
