ID.AM-08.145
Does your organization have a documented procedure for securely sanitizing data storage media before hardware is retired, decommissioned, reassigned, or sent for repairs?
Explanation
Data sanitization ensures that sensitive information cannot be recovered from storage media when hardware leaves your control. Without proper sanitization, confidential data, credentials, or intellectual property could be exposed to unauthorized parties even after physical possession of the hardware changes. Acceptable evidence would include a formal data sanitization policy document, procedure manual for IT staff that details the approved methods (such as secure wiping, degaussing, or physical destruction), and sanitization verification logs that document when and how media was sanitized before disposal or transfer.
Implementation Example
Securely sanitize data storage when hardware is being retired, decommissioned, reassigned, or sent for repairs or replacement
ID: ID.AM-08.145
Context
- Function
- ID: IDENTIFY
- Category
- ID.AM: Asset Management
- Sub-Category
- Systems, hardware, software, services, and data are managed throughout their life cycles

