Skip to main content

Secure sanitisation and disposal of storage media

How to ensure data cannot be recovered from electronic storage media.
Collection of usb sticks
CreativaImages via Getty Images

This guidance is for organisations who need to ensure that data held on electronic storage media can’t be read by unauthorised parties after it has left organisational control.

It will help organisations to protect data from being read by standard users with access to commercially available data-recovery tools, or by using forensic services. This is based on the protections proportionate for OFFICIAL data, as described in the Government Security Classifications Policy’s threat model.

Note: This guidance will not protect data from being read by a skilled, well-funded laboratory.

  • If media has stored data with an HMG security classification of SECRET or above, separate guidance should be followed, which is available from your normal NCSC point of contact (PoC).
  • Media that has been used for OFFICIAL data should not be re-used to store data of SECRET or above, even after sanitisation processes have been followed.




For devices where data may remain

If the above steps could not be completed, or if there’s no manufacturer-provided reset, it may not be possible to access all memory space in the device. This means that there is a residual risk that a skilled, well-funded data recovery laboratory could recover any data that persists on the device. In many cases this may not be a concern, however a risk owner needs to be comfortable with this. 

Where the data needs to be protected to level higher than OFFICIAL, the data owner may choose to implement additional protections, for example not allowing re-use in an environment where the loss of PERSONAL (or other especially sensitive data) is more likely. 


Published

Reviewed

Version

2.0