NIST Site Search
Google
Web NIST.org
NIST.gov
Product Research

Advertise on this site
Headlines

»Insecure Loading of Dynamic Link Libraries in Windows Applications
»VMware Releases Updates for ESX Service Console Packages
»Cisco Releases Security Advisory for IOS XR Software Border Gateway Protocol
»RealNetworks Releases Update to Address Vulnerabilities in RealPlayer
»Cisco Releases Advisories for Unified Communications Manager and Unified Presence
»APWG Fax Back Phishing Education Program
»Adobe Releases Security Bulletin for Shockwave Player
»Apple Releases Security Update 2010-005
»Microsoft Releases Security Advisory
»VideoLAN Releases a Security Advisory for VLC Media Player


Date published: not known
Details

»T-430: Apple QuickTime Flaw in QTPlugin.ocx ActiveX Control Lets Remote Users Execute Arbitrary Code
Apple QuickTime Flaw in QTPlugin.ocx ActiveX Control Lets Remote Users Execute Arbitrary Code
»T-429: WaspTime MS-SQL Database instance with blank password for sa account
WaspTime MS-SQL Database instance with blank password for sa account
»T-428: Vulnerability in Help and Support Center
Vulnerability in Help and Support Center
»T-427: VMWare WebAccess Vulnerability
VMWare WebAccess Vulnerability
»T-426: Microsoft Windows Shortcut 'LNK/PIF' Files Automatic File Execution Vulnerability
Microsoft Windows Shortcut 'LNK/PIF' Files Automatic File Execution Vulnerability
»T-425: Desktop Java running in web browsers
Desktop Java running in web browsers
»T-424: Windows TCP/IP Stack IcmpSendEcho2Ex() Bug Lets Local Users Deny Service
Windows TCP/IP Stack IcmpSendEcho2Ex() Bug Lets Local Users Deny Service
»T-423: Microsoft Security Advisory (2269637) - Insecure Library Loading Could Allow Remote Code Execution
Microsoft Security Advisory (2269637) - Insecure Library Loading Could Allow Remote Code Execution
»T-422: Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability
Adobe Flash Player and AIR (CVE-2010-2216) Unspecified Memory Corruption Vulnerability
»T-421: Multiple CACTI Security Vulnerabilities
Multiple CACTI Security Vulnerabilities
»T-420: Microsoft Windows TCP/IP IPv6 Extension Header Remote Denial of Service Vulnerability
Microsoft Windows TCP/IP IPv6 Extension Header Remote Denial of Service Vulnerability
»T-419: PHP 'ibase_gen_id()' Function off-by-one Buffer Overflow Vulnerability
PHP 'ibase_gen_id()' Function off-by-one Buffer Overflow Vulnerability
»T-418: Adobe Acrobat and Reader Font Parsing Remote Code Execution Vulnerability
Adobe Acrobat and Reader Font Parsing Remote Code Execution Vulnerability
»T-417: Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
»T-417: Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities


Date published: not known
Details

»ARF published as IETF standard
Abuse report format helps auto-handling of email complaints
»Microsoft releases new fix for DLL vulnerability
Earlier workaround believed to be too complex for most users.
»Malicious tweets link to fake TweetDeck update
Twitter resets passwords for accounts that appear to have been hacked.
»94% of Internet users befriend unknown 'good-looking woman'
Sensitiva data shared after two-hour chat.
»Investment boost for Quick Heal
Indian security firm gets hefty cash injection.
»41% of spam sent via Rustock botnet
Botnet spam back after short summer break.
»Avast gets $100m investment boost
Growth equity firm invests in Czech firm
»Computer chip giant buys AV giant
Intel becomes new owner of McAfee for the princely sum of $7.8bn
»AV-Test.org issues latest round of testing results
Symantec and Microsoft outdo Trend and McAfee in live tests.


Date published: not known
Details

»Networked Scanners Offer A Window Into The Enterprise, Researcher Says
Emerging Web-based features make it possible to capture document contents remotely from networked sc ...
»U.S. Businesses Could Lose Up To $1 Billion In Online Banking Fraud This Year
Small- to midsized businesses taking the biggest hit, experts say, but consumer banking customers co ...
»Product Watch: Verizon, VMware Team Up With Hybrid Cloud Service
New Verizon service offers private public-cloud option
»Could USB Flash Drives Be Your Enterprise's Weakest Link?
The Pentagon last week conceded that a USB flash drive carried an attack program inside a classified ...
»Delaware Contractor Mistakenly Posts Personal Data Of 22,000 Employees
State of Delaware contractor Aon mistakenly posts personal data of 22,000 retirees without randomiza ...
»IBM Corrects Unpatched Vulnerability Numbers After Google Challenge
X-Force Team at IBM revises data on vendors with most unpatched bugs in recent IBM X-Force 2010 Mid- ...
»Major Disruption of Pushdo Botnet Wasn't The Original Goal
Botnet's spam traffic cut by 80 percent
»China, Taiwan Nab 450 Suspects In Biggest Fraud Raid Ever
Law enforcement authorities in China, Taiwan seize cash, fraud "manuals" from alleged tele ...
»Four Best Practices For Tokenization
Going beyond Visa's best practices guide


Date published: not known
Details
NIST SP 800-88 Guidelines for Media Sanitization
Guidelines for Media Sanitization: Recommendations of the National Institute of Standards and Technology
on Monday 04 September 2006 email the content item print the content item
in NIST.gov Publications > Special Publications - SP 800 series

NIST Special Publication 800-88 was sponsored by the Homeland Security Department. Media Sanitization is an important subject and is required for all federal agencies. This document attempts to standardize how various media is sanitized before disposal or reuse.

Download the entire NIST SP 800-88 PDF (9/2006 Rev 1)

You may use the NIST.org Forum to ask questions or discuss this document.

Description from NIST.gov SP 800-88 (edited):

Information systems capture, process, and store information using a wide variety of media. This information is located not only on the intended storage media but also on devices used to create, process, or transmit this information. This media may require special disposition in order to mitigate the risk of unauthorized disclosure of information and to ensure its confidentiality. Efficient and effective management of information created, processed, and stored by an information technology (IT) system throughout its life (from inception through disposal) is a primary concern of an information system owner.

With the more prevalent use of increasingly sophisticated encryption, an attacker wishing to gain access to an organization’s sensitive information is forced to look outside the system itself for that information. One avenue of attack is the recovery of supposedly deleted data from media. This residual data may allow unauthorized individuals to reconstruct data and thereby gain access to sensitive information. Sanitization, done properly, can be used to thwart this attack by ensuring that deleted data cannot be easily recovered.

When storage media are transferred, become obsolete, or are no longer usable or required by an information system, it is important to ensure that residual magnetic, optical, or electrical representation of data that has been deleted is not easily recoverable. Sanitization refers to the general process of removing data from storage media, such that there is reasonable assurance, in proportion to the confidentiality of the data, that the data may not be retrieved and reconstructed.

This guide will assist organizations and system owners in making practical sanitization decisions based on the level of confidentiality of their information. It does not, and cannot, specifically address all known types of media; however, the described sanitization decision process can be applied universally.

---
The SP 800-88 document was created by the National Institute of Standards and Technology and is public domain (not subject to copyright).


NIST Special Publication # 800-88


Translate to: French German Italian Spanish Portuguese GTM_LAN_DUTCH Russian Chinese Arabic Korean English
Google Ads




NIST Site Menu
·Home

Current Security News
 
SANS Internet Storm Center, InfoCON: green

» Infocon: green

» Microsoft EMETv2 released, (Thu, Sep 2nd)
[02 Sep 2010 01:00pm]

» SDF, please!, (Thu, Sep 2nd)
[01 Sep 2010 06:50pm]

» Month of Undisclosed 0-day Bugs, (Wed, Sep 1st)
[01 Sep 2010 02:05pm]

» Microsoft issues updates to sysinternals ProcDump and Process Monitor: http://blogs.technet.com/b/sysinternals/archive/2010/08/30/updates-procdump-process-monitor-and-a-new-mark-s-blog-post.aspx, (Wed, Sep 1st)
[01 Sep 2010 10:29am]

» VMWARE releases 2 security advisories for ESX Service Console: http://lists.vmware.com/pipermail/security-announce/2010/000103.html and http://lists.vmware.com/pipermail/security-announce/2010/000104.html, (Wed, Sep 1st)
[01 Sep 2010 10:26am]

» Interesting PHP injection, (Tue, Aug 31st)
[31 Aug 2010 03:20am]

» Abandoned free email accounts, (Sun, Aug 29th)
[30 Aug 2010 05:38pm]

» Apple QuickTime potential vulnerability/backdoor, (Mon, Aug 30th)
[30 Aug 2010 05:24pm]

» New poll on mobile device security http://isc.sans.edu/poll.html, (Mon, Aug 30th)
[30 Aug 2010 04:26pm]

» Cisco IOS XR Software Border Gateway Protocol Vulnerability http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4411f.shtml, (Mon, Aug 30th)
[30 Aug 2010 03:51pm]

***
CNET News.com

» Facebook adds new remote log-out security feature
[02 Sep 2010 02:30pm]

» Nigerian scam tops list of decade's online cons
[02 Sep 2010 11:16am]

» India wants local servers from RIM, Google, Skype
[02 Sep 2010 10:45am]

» Twitter plans to record all links clicked
[02 Sep 2010 12:33am]

» China requires cell phone subscriber IDs
[01 Sep 2010 05:40pm]

» Quantum crypto cracked, researchers say
[01 Sep 2010 11:48am]

» Sweden reopens rape probe of Wikileaks founder
[01 Sep 2010 10:35am]

» Cars: The next hacking frontier?
[31 Aug 2010 12:07pm]

» Gmail, Skype now in India's crosshairs
[31 Aug 2010 10:47am]

» 3M to buy biometrics firm Cogent for $943 million
[30 Aug 2010 09:35am]

» RIM sidesteps BlackBerry ban in India
[30 Aug 2010 09:29am]

» 'LOL is this you?' spam spreading via Facebook chat
[27 Aug 2010 06:53pm]

» Google working on Gmail spam issue
[27 Aug 2010 12:13pm]

» RIM extends olive branch to Indian government
[26 Aug 2010 02:00pm]

» Bad flash drive caused worst U.S. military breach
[25 Aug 2010 04:37pm]

***
Computerworld Security News

» To boost security, Facebook adds remote logout
[02 Sep 2010 03:01pm]

» Botnet takedown may yield valuable data
[02 Sep 2010 04:25am]

» 3Par faces patent infringement lawsuit
[01 Sep 2010 05:04pm]

» Discover to get $5M from Heartland for '08 data breach
[01 Sep 2010 03:45pm]

» DARPA launches insider threat detection effort for military
[01 Sep 2010 03:03pm]

» Miami man pleads guilty in ID theft case
[01 Sep 2010 02:41pm]

» More Security News

***


***


More IT Security
News Feeds
More Sponsors

Advertise on this site
NIST - Books You Need

NIST Bookstore
RSS Feeds
Our news can be syndicated by using these rss feeds.
rss1.0
rss2.0
rdf
Add to NetVibes
Add to Bloglines
Add to NewsGator
Add to Google
Add to My Yahoo
Add to My MSN
Add to Technorati
Add to Pluckit
Add to My AOL
Subscribe in FeedLounge
Add to ProtoPage

Symantec News

NIST.org is in no way connected to the U.S. government site NIST.gov

This site is © John Herron, CISSP. All Rights Reserved.

Please visit daily to stay up to date on all your IT Security compliance issues.

http://www.nist.org -
Hosted by BlueHost. We've never had a better hosting company.