A company is decommissioning a server farm containing hundreds of hard drives that stored various classifications of data, including 'Confidential' customer PII and 'Public' marketing materials. To ensure compliance with data sanitization standards for the 'Confidential' data while being cost-effective for 'Public' data, which combination of sanitization methods would be MOST appropriate?
- APhysical destruction for 'Confidential' data, overwriting (purge) for 'Public' data.
- BPhysical destruction for 'Confidential' data, degaussing for 'Public' data.
- CDegaussing for 'Confidential' data, logical deletion for 'Public' data.
- DOverwriting (purge) for 'Confidential' data, clear (logical deletion) for 'Public' data.
Show answer & explanationAnswer & explanation
Correct answer: D. Overwriting (purge) for 'Confidential' data, clear (logical deletion) for 'Public' data.
For 'Confidential' data, NIST SP 800-88 recommends Purge (e.g., overwriting) as a strong method, or Destroy (physical destruction) for ultimate assurance. Overwriting (Purge) is a cost-effective and secure method for data that must be rendered unrecoverable by common means. For 'Public' data, which has a lower sensitivity, Clear (logical deletion or single-pass overwriting) is often sufficient, as the risk of recovery is acceptable, or the data has no sensitivity. Degaussing renders drives unusable and is more appropriate for sensitive data if reuse is not a concern. Physical destruction is the most secure but also the most expensive and prevents reuse.
Why the other options are wrong
- A. Physical destruction is appropriate for 'Confidential' data, but overwriting (purge) is generally overkill for 'Public' data if simple clear is sufficient for cost-effectiveness.
- B. Physical destruction is excellent for 'Confidential' data, but degaussing is overkill and costly for 'Public' data that might be reused or has low sensitivity.
- C. Degaussing is suitable for sensitive data, but logical deletion is generally insufficient for 'Public' data if there's any chance of recovery, even low risk.
Data Sanitization Methods (NIST SP 800-88)
Techniques to render data inaccessible for a given level of effort, ranging from simple deletion to physical destruction, ensuring data is removed from storage media.
- Clear: Logical deletion or simple overwrite, data may be recoverable with advanced tools.
- Purge: Overwriting multiple times, degaussing, or cryptographic erase; renders data unrecoverable by state-of-the-art lab techniques.
- Destroy: Physical destruction (shredding, pulverizing); renders data recovery impossible.
Memory trick: Clear for casual, Purge for private, Destroy for critical.