Many people assume that simply deleting files or formatting a device means the data is completely gone.

In reality, some data may still remain on hard drives, SSDs, notebooks, servers, smartphones, and other storage devices. In some cases, that information can potentially be recovered using specialized software or tools.

This is why organizations that handle customer information, employee records, financial data, or confidential business information should prioritize secure data erasure before selling, donating, reusing, recycling, or disposing of IT equipment.

One of the most widely referenced guidelines for this purpose is NIST SP 800-88, which provides guidance on Media Sanitization and helps organizations select appropriate methods for securely erasing or destroying data based on the type of device and the level of data risk.

What Is NIST 800-88?

NIST SP 800-88 provides guidelines for securely sanitizing data stored on electronic media and storage devices.

The guidelines were developed by the National Institute of Standards and Technology (NIST), an agency of the U.S. Department of Commerce that plays an important role in developing standards and guidance related to technology, cybersecurity, and information security.

In simple terms, NIST 800-88 helps organizations answer an important question: “Before an IT device is retired, how should the data stored on it be handled to ensure that it is secure?”

The current version, NIST SP 800-88 Rev.2, places greater emphasis on developing a systematic and verifiable Media Sanitization process across an organization.

What Is Media Sanitization?

Media Sanitization is the process of making data stored on a device or storage medium inaccessible according to an appropriate level of security.

Devices and media that may require sanitization include:

  • Hard Disk Drives (HDDs)
  • Solid-State Drives (SSDs)
  • Notebooks and desktop computers
  • Servers and storage systems
  • Smartphones and tablets
  • USB flash drives
  • Certain network devices

It is important to understand that Media Sanitization is not the same as simply deleting a file.

When a user presses Delete, the operating system may remove the reference to the file without immediately removing all of the underlying data. In some situations, that information may still be recoverable using specialized software or forensic tools.

Why Might Formatting a Device Not Be Enough?

Imagine a company has 100 old employee notebooks that it plans to sell.

Those devices may previously have contained information such as:

  • Customer information
  • Employee records
  • Accounting documents
  • Emails and internal company files
  • Passwords or login information
  • Project information
  • Personal data
  • Confidential business information

If the organization simply deletes the files or formats the devices without confirming that the data has been properly sanitized, there may still be a risk that the original information could be recovered.

For this reason, securely erasing data before selling old computers or IT equipment should be an important part of an organization’s asset disposal process.

How Does NIST 800-88 Classify Data Sanitization Methods?

NIST guidance describes several key approaches to Media Sanitization, including Clear, Purge, and Destroy.

Each method is suitable for different situations.

1. Clear

Clear is a sanitization approach designed to reduce the risk of data being recovered through standard interfaces and commonly available methods.

It may be suitable when a device will continue to be used within the organization or when the sensitivity of the information does not require a higher level of sanitization.

The important point is that the selected method must be appropriate for the type of storage technology being used.

2. Purge

Purge provides a higher level of protection against data recovery.

One possible technique is Cryptographic Erase, which uses encryption-related mechanisms to make previously stored information inaccessible.

This approach may be suitable for certain modern devices, such as SSDs or storage systems that support the required technology.

The appropriate technique should always be selected according to the device, storage technology, firmware capabilities, and organizational security requirements.

3. Destroy

If a device no longer needs to be reused, or if it contains highly sensitive information, an organization may choose Physical Destruction.

Examples include:

  • Hard drive shredding
  • SSD destruction
  • Physical shredding of storage media
  • Destruction of the components where data is stored

The objective is to prevent the storage media from being reused to access the original data.

Should You Choose Clear, Purge, or Destroy?

There is no single method that is suitable for every organization or every type of device.

Before choosing a Data Erasure or Data Destruction method, organizations should consider several factors.

How sensitive is the data?

General business information may require a different level of protection from personal data, financial information, intellectual property, or highly confidential business records.

What type of device is it?

HDDs, SSDs, flash storage, and server storage systems use different technologies. Therefore, the same sanitization method should not automatically be applied to every type of device.

What will happen to the device afterward?

If the equipment will be reused, refurbished, or resold, the organization may want to preserve the device while securely sanitizing the data.

If the device is damaged, obsolete, or no longer required, physical destruction may be a more appropriate option.

What would happen if the data were exposed?

The greater the potential impact of a data breach, the stronger the sanitization controls should be.

How Does NIST 800-88 Relate to Hard Drive Destruction?

A common question is:

“Do all hard drives need to be physically destroyed?”

Not necessarily.

If a hard drive is still usable and can be securely sanitized using an appropriate method, physical destruction may not always be required.

However, if the information is highly sensitive, the device is damaged, or the organization cannot reliably verify the sanitization process, physical destruction of the storage media may be the more appropriate choice.

This approach can help organizations balance two important objectives:

Data Security
Protecting sensitive information and reducing the risk of unauthorized data recovery.

and

Sustainability
Allowing suitable IT equipment to be reused, refurbished, or resold instead of unnecessarily destroying every device and generating additional electronic waste.

How Does NIST 800-88 Relate to ITAD?

For organizations with large numbers of computers, notebooks, servers, and other IT assets, Media Sanitization is often part of a broader process known as IT Asset Disposition (ITAD).

ITAD is the process of managing IT equipment at the end of its lifecycle.

Depending on the condition and value of the equipment, assets may be:

  • Reused
  • Refurbished
  • Resold
  • Recycled
  • Destroyed

One of the most important steps in the ITAD process is ensuring that data is properly managed before an asset leaves the organization’s control.

Even when an old computer has little financial value, the information stored inside it may still be extremely valuable or sensitive.

This is why secure data sanitization should be an important part of any responsible IT asset disposition program.

A Good Data Sanitization Process Should Be Verifiable

Choosing an appropriate data sanitization method is only part of the process.

Organizations should also consider maintaining records and evidence that allow the process to be verified and audited later.

This may include:

  • Device serial numbers
  • Date of sanitization or destruction
  • Sanitization method used
  • Verification or validation results
  • Person or organization responsible
  • Certificates or supporting documentation

These records can help demonstrate that each device has been processed appropriately.

This is especially important for organizations with requirements relating to Data Protection, Cybersecurity, Compliance, Information Security, and Corporate Governance.

What Should Organizations Do Before Selling or Disposing of Old Computers?

When replacing computers or notebooks, organizations should consider more than simply transporting or selling their old equipment.

Before an IT asset leaves the organization, it is useful to ask:

  1. What information is stored on this device?
  2. How sensitive is the information?
  3. Will the device be reused, resold, refurbished, or recycled?
  4. Which data sanitization method is appropriate?
  5. Can the organization verify that the data has been securely sanitized?
  6. Is there documentation or evidence of the process?

Having a clear process in place can significantly reduce the risk of a Data Breach after IT equipment leaves the organization’s control.

NIST 800-88 Explained Simply

NIST SP 800-88 provides guidance to help organizations securely manage data stored on IT equipment before those devices are retired or transferred.

The key objective is not simply to make a file disappear from the screen.

The goal is to ensure that sensitive information cannot be accessed or recovered at an unacceptable level of risk after the device leaves the organization’s control.

Before selling, donating, refurbishing, reusing, or recycling IT equipment, organizations should therefore implement an appropriate Media Sanitization and Data Destruction process based on the type of device, sensitivity of the information, and associated security risks.

An old device may have reached the end of its useful life.

But the data stored inside it may still be valuable.

Proper data sanitization is therefore an essential part of Data Security, IT Asset Disposition (ITAD), and responsible IT lifecycle management.

Source : NIST SP 800-88 Media Erasure Guidelines