NIST Site Search
Search NIST.GOV
Custom Search
[Official NIST.GOV TIME]
Product Research

Advertise on this site
NIST SP 800-88 Guidelines for Media Sanitization
Guidelines for Media Sanitization: Recommendations of the National Institute of Standards and Technology
on Monday 04 September 2006 print the content item {PDF=create pdf file of the content item^plugin:content.52}
in NIST.gov Publications > Special Publications - SP 800 series

NIST Special Publication 800-88 was sponsored by the Homeland Security Department. Media Sanitization is an important subject and is required for all federal agencies. This document attempts to standardize how various media is sanitized before disposal or reuse.

Download the entire NIST SP 800-88 PDF (9/2006 Rev 1)

You may use the NIST.org Forum to ask questions or discuss this document.

Description from NIST.gov SP 800-88 (edited):

Information systems capture, process, and store information using a wide variety of media. This information is located not only on the intended storage media but also on devices used to create, process, or transmit this information. This media may require special disposition in order to mitigate the risk of unauthorized disclosure of information and to ensure its confidentiality. Efficient and effective management of information created, processed, and stored by an information technology (IT) system throughout its life (from inception through disposal) is a primary concern of an information system owner.

With the more prevalent use of increasingly sophisticated encryption, an attacker wishing to gain access to an organization’s sensitive information is forced to look outside the system itself for that information. One avenue of attack is the recovery of supposedly deleted data from media. This residual data may allow unauthorized individuals to reconstruct data and thereby gain access to sensitive information. Sanitization, done properly, can be used to thwart this attack by ensuring that deleted data cannot be easily recovered.

When storage media are transferred, become obsolete, or are no longer usable or required by an information system, it is important to ensure that residual magnetic, optical, or electrical representation of data that has been deleted is not easily recoverable. Sanitization refers to the general process of removing data from storage media, such that there is reasonable assurance, in proportion to the confidentiality of the data, that the data may not be retrieved and reconstructed.

This guide will assist organizations and system owners in making practical sanitization decisions based on the level of confidentiality of their information. It does not, and cannot, specifically address all known types of media; however, the described sanitization decision process can be applied universally.

---
The SP 800-88 document was created by the National Institute of Standards and Technology and is public domain (not subject to copyright).


NIST Special Publication # 800-88


Translate to: French German Italian Spanish Portuguese GTM_LAN_DUTCH Russian Chinese Arabic Korean English
Google Ads




Headlines

»NIST Forensic Science Standards Committees to Hold First Public Meetings in February 2015
»NIST Security Guide Walks Organizations Through the Mobile App Security Vetting Process
»Open-Source Software for Quantum Information
»NIST Requests Round Two Comments on its Cryptographic Standards Process
»Symposium to Focus on Future of Voting Systems
»NIST Meeting: Cybersecurity Is a Key Ingredient In the Manufacturing Mix
»Future of Voting Systems Symposium II
»Global City Teams Challenge Tech Jam
»NIST Announces Initial Members of Forensic Science Digital Evidence Subcommittee
»Cybersecurity Center Invites Feedback on Securing Medical Devices
»NIST Issues New Revision of Guide to Assessing Information Security Safeguards
»Cloud Metrics Could Provide the Goldilocks Solution to Which Cloud Vendor Is aposJust Rightapos
»Filling the Gap: NIST Document to Protect Federal Information in Nonfederal Information Systems
»Cyber Security: Your Mother Was Right, Sharing is Good, And NIST Has Some Help on How
»2014 Cybersecurity Education Meeting Emphasizes Presidential Ready to Work Initiative


Date published: not known
Details

»Apple Releases Security Updates for OS X, Safari, iOS and Apple TV
Original release date: January 27, 2015 Apple has released security updates for OS X, Safari, ...
»Linux "Ghost" Remote Code Execution Vulnerability
Original release date: January 27, 2015 | Last revised: January 28, 2015 The Linux GNU C Libr ...
»Security Advisory for Adobe Flash Player
Original release date: January 26, 2015 Adobe has released Flash Player desktop version 16.0.0.296 to address a critical vulnerability (CVE-2015-0311) in 16.0.0.287 and earlier versions for Windows and Macintosh. This vulnerability could allow an attacker to take control of the affected system.Users and administrators are encouraged to review Adobe Security Bulletin APSB15-01 and apply the necessary updates. This product is provided subject to this Notification and this Privacy & Use policy.
»IC3 Releases Alert for a Scam Targeting Businesses
Original release date: January 24, 2015 The Internet Crime Complaint Center (IC3) has release ...
»FBI Releases "Ransomware on the Rise"
Original release date: January 23, 2015 The FBI has released an article addressing ransomware ...
»Google Releases Security Updates for Chrome
Original release date: January 23, 2015 Google has released Chrome 40.0.2214.91 for Windows, ...
»Adobe Releases Security Updates for Flash Player
Original release date: January 22, 2015 Adobe has released security updates to address a vuln ...
»Oracle Releases January 2015 Security Advisory
Original release date: January 20, 2015 Oracle has released its Critical Patch Update for Jan ...
»Ubuntu Releases Security Updates
Original release date: January 20, 2015 Ubuntu has released security updates to address multi ...
»Affordable Care Act Phishing Campaign
Original release date: January 15, 2015 US-CERT is aware of a phishing campaign purporting to ...


Date published: not known
Details

»VB2014 paper: Ubiquitous Flash, ubiquitous exploits and ubiquitous mitigation
Chun Feng and Elia Florio analyse two Flash Player vulnerabilities and an IE one where Flash provide ...
»Frequently asked questions about VB2015 conference submissions
No, it doesn't have to be about malware and no, it doesn't have to be deeply technical either! Last ...
»Linux systems affected by 'GHOST' vulnerability
Proof-of-concept email gives remote access to Exim mail server. If you administer Linux-based system ...
»VB2014 paper: Design to discover: security analytics with 3D visualization engine
Thibault Reuille and Dhia Mahjoub use DNS data to look for clusters of malicious domains. Since the ...
»Adobe to patch Flash Player zero-day next week
Patch due next week as malvertising leads to Bedep trojan downloader. As the news of a zero-day vuln ...
»Alleged Flash Player zero-day used in Angler exploit kit
Adobe 'investigating reports'. Vulnerable browser plug-ins are one of the most important infection v ...
»Research paper profiles victims of targeted attacks
Large organisations working in national security and international affairs run highest risk. Anyone ...
»Paper: Nesting doll: unwrapping Vawtrak
Raul Alvarez unwraps the many layers of an increasingly prevalent banking trojan. Banking trojans re ...
»VB2014 paper: OPSEC for security researchers
Vicente Diaz teaches researchers the basics of OPSEC. Since the close of the VB2014 conference in Se ...


Date published: not known
Details

»Analyze This?
»Google Paid Over $1.5 Million In Bug Bounties In 2014
Mobile apps developed by Google now included in its Vulnerability Reward Program.
»How The Skills Shortage Is Killing Defense in Depth
It used to be easy to sell specialized security gizmos but these days when a point product gets pitc ...
»Takeaways from International Data Privacy Day: The Internet of Things
Event looks at the future of data use and how we can - and should - protect personal privacy.
»ZeroAccess Click-Fraud Botnet Back In Action Again
After a six-month hiatus, the much-diminished P2P botnet is up to its old tricks.
»Why Iran Hacks
Iran is using its increasingly sophisticated cyber capabilities to minimize Western influence and es ...
»'Ghost' Not So Scary After All
The latest open-source Linux vulnerability is serious but some security experts say it's not that ea ...
»Small Changes Can Make A Big Difference In Tech Diversity
There's no doubt that many employers feel most comfortable hiring people like themselves. But in Inf ...
»Half Of Enterprises Worldwide Hit By DDoS Attacks, Report Says
New data illustrates how distributed denial-of-service (DDoS) attacks remain a popular attack weapon ...


Date published: Sun, 01 Feb 2015 15:14:24 EST
Details
Main Menu
· Home
Current Security News
 
SANS Internet Storm Center, InfoCON: green

» Infocon: green

» Improving SSL Warnings, (Sun, Feb 1st)
[01 Feb 2015 09:44am]

» Beware of Phishing and Spam Super Bowl Fans!, (Sat, Jan 31st)
[30 Jan 2015 09:43pm]

» ISC StormCast for Friday, January 30th 2015 http://isc.sans.edu/podcastdetail.html?id=4335, (Fri, Jan 30th)
[29 Jan 2015 09:05pm]

» Blindly confirming XXE, (Thu, Jan 29th)
[29 Jan 2015 11:43am]

» ISC StormCast for Thursday, January 29th 2015 http://isc.sans.edu/podcastdetail.html?id=4333, (Thu, Jan 29th)
[28 Jan 2015 08:34pm]

» Adobe Flash Update Available for CVE-2015-0311 & -0312, (Wed, Jan 28th)
[28 Jan 2015 01:23pm]

» GHOST glibc gethostbyname() Vulnerability: https://www.youtube.com/watch?v=218JiCBpUTM, (Wed, Jan 28th)
[28 Jan 2015 09:01am]

» ISC StormCast for Wednesday, January 28th 2015 http://isc.sans.edu/podcastdetail.html?id=4331, (Wed, Jan 28th)
[28 Jan 2015 08:43am]

» VMware Security Advisories - 1 New, 1 Updated, (Wed, Jan 28th)
[27 Jan 2015 05:48pm]

» New Critical GLibc Vulnerability CVE-2015-0235 (aka GHOST), (Tue, Jan 27th)
[27 Jan 2015 04:56pm]

***
CNET News.com

» Microsoft defends opening Hotmail account of blogger in espionage case
[20 Mar 2014 06:47pm]

» Syria's Internet goes dark for several hours
[20 Mar 2014 04:25pm]

» Symantec fires CEO Steve Bennett
[20 Mar 2014 03:07pm]

» Microsoft sniffed blogger's Hotmail account to trace leak
[20 Mar 2014 01:28pm]

» Microsoft sniffed private Hotmail account to trace trade secret leak
[20 Mar 2014 01:28pm]

» IBM's new services zero in on fraud, financial crime
[20 Mar 2014 07:31am]

» Despite assault on privacy, Page sees value in online openness
[19 Mar 2014 08:00pm]

» Hackers transform EA Web page into Apple ID phishing scheme
[19 Mar 2014 05:21pm]

» NSA top lawyer says tech giants knew about data collection
[19 Mar 2014 02:57pm]

» Microsoft touts study showing the cost of pirated software
[19 Mar 2014 06:55am]

» Microsoft touts study showing cost of malware in pirated software
[19 Mar 2014 06:55am]

» How to spy on your lover, the smartphone way
[18 Mar 2014 01:24pm]

» Mt. Gox update lets users see their Bitcoin balances
[18 Mar 2014 06:38am]

» Fake Malaysia Airlines links spread malware
[17 Mar 2014 05:12pm]

» IBM: No, we did not help NSA spy on customers
[17 Mar 2014 01:15pm]

***

***



***


More IT Security
News Feeds
More Sponsors

Advertise on this site
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf
Symantec News

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.
{THEMEDISCLAIMER}