Media sanitisation and destruction
Listen to this lesson
Every episode of this course is also a podcast: listen on Spotify.
This episode is a study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.
Why this matters
Deleting a file does not remove its data. Deleting a partition or formatting a disk does not remove it either. In most cases, the operating system simply marks the space as available, and the old data stays on the disk until something overwrites it, readable by anyone with free recovery software. Studies of second-hand drives bought online have repeatedly found confidential business and personal data on disks their previous owners believed were empty.
Every disk, tape and flash device that has held an organisation's data will eventually leave its control, whether for repair, resale, recycling or the bin. Sanitisation is making sure no data leaves with it. This lesson covers the methods, why solid-state drives need different treatment, the fastest method of all, and the records and custody that prove it was done.
The lesson
Wiping, degaussing and shredding, and when each is enough
The widely used standard for sanitisation, NIST Special Publication 800-88, groups methods into three levels according to how determined an attacker they defeat:
- Clear: protects against ordinary recovery tools, typically by overwriting all user-addressable storage with new data.
- Purge: protects against recovery even with laboratory techniques, using methods such as the drive's own built-in sanitise commands, cryptographic erase, or degaussing.
- Destroy: makes the media physically unusable, so that recovery is impossible and the media cannot be reused.
The main methods:
- Wiping or overwriting writes over every sector, with zeros, ones or random data. For traditional hard disk drives, a single complete pass is considered sufficient by current guidance. The drive can then be reused or sold. Tools range from dedicated wiping software to the sanitise functions in server firmware and management controllers.
- Degaussing exposes magnetic media, hard drives and tapes, to a very strong magnetic field that scrambles the recorded data. It is fast, but it also destroys the drive's own servo information, so a degaussed hard drive can never be used again. It has no effect on solid-state drives, which do not store data magnetically.
- Physical destruction means shredding, crushing, drilling, disintegration or incineration. Shredding into small particles is the standard for the most sensitive data. Drilling a hole or two through a drive is quick, but leaves most platter or flash chip area intact and recoverable in a laboratory, so it is a weak method for highly sensitive data.
The right method depends on the data's classification, from the data retention lesson, and on whether the media will leave the organisation. A drive reused internally for similar data may only need clearing; a drive that held restricted data and is leaving the building should be purged or destroyed.
SSDs, and why overwriting them is unreliable
Overwriting works on hard disk drives because writing to a sector replaces what was in that sector. Solid-state drives do not work that way.
An SSD's controller hides the physical flash from the operating system. When the system writes to a location, the controller usually writes the new data to a different physical block, and marks the old one for later erasure. This spreads wear evenly across the flash, a process called wear levelling, but it means an overwrite may not touch the old data at all. SSDs also hold over-provisioned spare capacity, invisible to the operating system, and remapped blocks retired because of wear, which software overwriting cannot reach. The old data may survive in any of these places.
So SSDs and other flash media are sanitised by:
- the drive's built-in sanitise or secure erase commands, part of the ATA, SCSI and NVMe standards, which instruct the controller to erase every block, including hidden areas; implementation quality varies between manufacturers, so verification matters;
- cryptographic erase, described next;
- physical destruction, shredded to particles small enough to destroy the individual flash chips, when the data is highly sensitive or the drive's commands cannot be trusted.
Degaussing, as noted above, does nothing to an SSD.
Cryptographic erase
Many modern drives, including self-encrypting drives and most SSDs, encrypt everything written to them with an internal media encryption key, whether or not the user has turned on any encryption feature. Data on the flash or platters is only ever ciphertext.
Cryptographic erase (CE) sanitises such a drive by destroying that key and generating a new one. Without the old key, the old data is unreadable ciphertext, whatever physical blocks it still occupies. It takes seconds, even on the largest drives, and leaves the drive reusable.
The same principle applies more broadly. Data protected by BitLocker, LUKS or database encryption, as in the encryption lesson, becomes unreadable if every copy of its keys is destroyed, including escrowed recovery keys.
Cryptographic erase has conditions:
- it is only as good as the encryption: the key must have been generated and handled properly, and data must never have been written unencrypted;
- it depends on the drive's firmware actually destroying the key, which cannot easily be checked from outside;
- for the most sensitive data, organisations often combine it with another method, such as cryptographic erase followed by overwriting, or by physical destruction.
In cloud and virtualised environments, where the organisation never has the physical disks, cryptographic erase by destroying keys is often the only sanitisation available, which is one reason to encrypt cloud storage with keys the organisation controls.
Certificates of destruction
Sanitisation must be provable. Regulations and audits require organisations to show that data was destroyed, not merely to say so, and in the event of a breach investigation, the question "what happened to that drive?" needs a documented answer.
When media is destroyed or sanitised by a specialist company, the company issues a certificate of destruction (or of sanitisation). A useful certificate records:
- the serial number of each drive or item, so it can be matched against the inventory;
- the method used, and the standard it meets;
- the date and location;
- who performed and who witnessed it.
A certificate listing only "40 hard drives destroyed" does not show which drives, and cannot prove a particular drive was among them.
When sanitisation is done in-house, the same records are kept internally, often generated by the wiping tool as a report per drive, and the inventory or CMDB is updated to show each item's disposal. Some organisations witness destruction, either in person or on video, or have it done on site by a mobile shredding service, so drives never leave their control intact.
Chain of custody for drives leaving the building
Between leaving the server and being destroyed, a drive is at its most exposed. It is no longer protected by the server's physical security or encryption keys held by the server, and it may pass through several hands: the technician who removed it, a storage room, a courier, and the disposal company.
Chain of custody is the documented record of every hand the drive passes through. Each transfer is recorded with who handed it over, who received it, when, and the drive's serial number, and signed by both. If a drive goes missing, the chain shows where it was last accounted for.
Good practice for drives awaiting disposal:
- keep them in locked storage, as the asset lesson described for media, with a count that matches the inventory;
- move them in locked, sealed containers, with seal numbers recorded;
- use vetted disposal companies, contractually bound to documented processes;
- consider the keep your drive option on support contracts, so failed drives are not returned to the vendor with data on them;
- reconcile the disposal company's certificate against the chain of custody records, serial number by serial number.
The process is tedious by design. Each record is small, and together they are what allow the organisation to say with confidence that no drive left with its data.
Try it
An interactive exercise runs here: a real Linux machine in your browser that checks each step. The commands above work on any Linux machine too.
Practise what you just read
1. An administrator overwrote an SSD several times with zeros before selling it. Why might data remain?
Select one
Show answer
C. The SSD controller writes new data to different physical blocks and keeps over-provisioned and remapped areas the OS cannot address. Built-in sanitise commands or cryptographic erase are needed instead.
2. Why does degaussing not sanitise a solid-state drive?
Select one
Show answer
A. Degaussing scrambles magnetic media such as hard drives and tapes. Flash memory stores data as electrical charge, so a magnetic field leaves the data intact.
3. How does cryptographic erase sanitise a self-encrypting drive?
Select one
Show answer
B. Everything on a self-encrypting drive is encrypted with an internal key. Destroying and replacing that key leaves the old data as unreadable ciphertext, in seconds, and the drive reusable.
7 more questions on this objective are part of the full course.
Hands-on labs
Part of the free CompTIA Server+ SK0-005 course — 51 lessons and 72 hands-on labs.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.