[ORGANIZATION NAME] Data Destruction Policy
- Version
- 1.0
- Effective Date
- [DATE]
- Review Date
- [DATE + 1 YEAR]
Approved by: [NAME, TITLE]
1. Purpose and Scope
This policy establishes requirements for the secure destruction of data-bearing media to protect [ORGANIZATION NAME]'s information assets and ensure compliance with applicable laws and regulations.
2. Definitions
- Data-Bearing Media: Any device capable of storing electronic data.
- Data Sanitization: The process of permanently removing data from media.
- Clear: Applying logical techniques to sanitize data in all user-addressable storage locations (NIST 800-88).
- Purge: Applying physical or logical techniques that render target data recovery infeasible (NIST 800-88).
- Destroy: Rendering media incapable of storing or transmitting data (NIST 800-88).
- Chain of Custody: The documented, unbroken record of physical possession of media.
3. Data Classification and Destruction Requirements
- Confidential/Restricted Data (ePHI, PII, financial records): Destroy method required.
- Internal/Sensitive Data: Purge method required.
- Public/Non-sensitive Data: Clear method acceptable.
4. Approved Destruction Methods
- Clear: NIST 800-88 compliant software overwrite.
- Purge: NSA EPL-listed degaussing or cryptographic erase (SSDs/NVMe).
- Destroy: Physical shredding using NSA/CSS EPL standards equipment.
5. Chain of Custody Requirements
All data-bearing media must be tracked from collection through final disposition with: asset inventory with serial numbers, transport documentation, processing records, and Certificate of Destruction.
6. Documentation and Recordkeeping
Certificates of Destruction must be retained for a minimum of [7 YEARS / per applicable regulation].
7. Vendor Requirements
All third-party ITAD vendors must hold R2v3 certification and NAID AAA certification.
8. Employee Responsibilities
All employees must report data-bearing media for disposal through the approved ITAD process and never dispose of media in standard trash or recycling.
9. Policy Review Schedule
This policy must be reviewed annually.
10. Compliance References
HIPAA 45 CFR § 164.310 · SOX Section 802 · GLBA 16 CFR Part 314 · PCI-DSS v4.0 Req. 9.4.6–9.4.7 · CMMC 2.0 MP.2.119 · NIST SP 800-88 Rev. 1