Sidebar: Best Practices for Data Destruction
Computerworld -
Here's a summary of best practices used by Vince Tuesday when using an IT equipment disposal vendor to ensure complete destruction of all data. Tuesday (not his real name) is a security manager at a large financial services company and a former contributor to Computerworld's Security Manager's Journal.
Physical Disposal Practices
- Items to be removed from site are placed in a storage area within the organization's IT premises.
- Removable drives are checked, asset tags are scanned, and a report of the assets to be removed is generated for final checking and audit-trail purposes.
- Once the report is signed off on, items are removed from the site. Specific security guidelines for transportation are enforced, such as providing access to known, registered personnel only; conducting security checks on courier staff; using unmarked vans and specifying that vans may not be left unattended or unlocked; and so on.
- When arriving at the supplier's facility, the assets are booked into the supplier's system. A report is sent immediately for comparison with the removal report to ensure that all assets were received.
- Prior to processing, equipment is held separately from that of other customers.
- Company tags are removed during processing, before disposal or resale.
- Unannounced inspections of the supplier's premises are permitted in the contract.
Data Sanitization Practices
- Data is wiped using a DOD three-pass algorithm with software certified by authorities such as the British Communications Electronic Security Group (baseline and enhanced), U.S. Department of Defense (DOD 5220.22-M) plus other international standards. This service is used on servers (Unix and Intel-based), disc arrays, laptops, desktops and PDAs.
- When the disk can't be accessed, it is removed and and then drilled in order to destroy it. The system unit is then recycled as component spares.
- If removable media is found, it is offered to the customer for secure return or destruction.
- On completion of data erasure, a certificate (per batch) is provided to the customer.
- Printers and faxes have their memories purged using setup menus (or via a disk erasure utility, if it has a hard disk).
- Mobile phones are wiped by checking for SIM cards (and returning if found) and erasing via menus.
Additional Resources


White Papers & Webcasts
Hidden Cash: Maximizing the Value of Surplus Technology in a Down Economy
In today's tightened economy, all major technology purchases are being carefully scrutinized to ensure that each new piece of hardware and software can...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Your Network at Half the Price: Slash Network Hardware Costs With Pre-Owned Equipment
Pre-owned networking equipment is certainly less expensive than the new variety, but IT managers are often challenged to know when and how to...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
Impact of the Dramatic Increase in Devices on the Cost to Support
This white paper describes the challenges that CIOs will face in coming years due to a dramatic increase in the number of devices...
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
Help Customers Preserve and Share Memories
As digital cameras became more and more prevalent, many photofinishers bemoaned the demise of their traditional film and processing business model. Digital posed...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
For Best Results, Think Beyond the Box
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to...
Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....
Subscribe to Computerworld
