🔒 Free Onsite Hard Drive Shredding · Witnessed Destruction · Greater Phoenix AreaSee Mobile Shredding
ITAD REFERENCE GUIDE

ITAD Glossary: Complete IT Asset Disposition Terminology

The definitive reference for IT Asset Disposition, data destruction, and electronics recycling terminology. Used by IT managers, compliance officers, and sustainability professionals.

A

Asset Audit

A comprehensive inventory and assessment of all IT equipment within an organization, documenting make, model, serial number, condition, and data-bearing status. Asset audits are the first step in the ITAD process and provide the foundation for data destruction planning and value recovery assessment.

Asset Manifest

A detailed document listing all IT assets collected for ITAD processing, including device type, manufacturer, model, serial number, and condition. Asset manifests are part of the chain-of-custody documentation required for HIPAA, SOX, and other compliance frameworks.

B

Blancco

A leading certified data erasure software used for NIST 800-88 compliant data wiping. Blancco generates tamper-proof erasure reports that serve as Certificates of Data Destruction for compliance purposes.

Buyback Program

An ITAD service where the provider purchases qualifying retired IT equipment at fair market value after certified data destruction. Buyback programs provide immediate cash recovery for organizations with recent-generation hardware.

C

Certificate of Data Destruction (CODD)

See Certificate of Destruction.

Certificate of Destruction (COD)

A legal document issued by a certified data destruction provider documenting the secure destruction of specific data-bearing devices. Includes device serial number, destruction method, date, technician, and certification standards met.

Chain of Custody

The documented, unbroken sequence of custody, control, transfer, and disposition of IT assets from client facility to final destruction or remarketing. Required for HIPAA, DoD, and most enterprise compliance frameworks.

Clear (NIST 800-88)

The lowest of three NIST 800-88 sanitization methods, using software overwriting to remove data from accessible storage locations. Suitable for media being repurposed within the same organization.

CMMC (Cybersecurity Maturity Model Certification)

A DoD framework requiring defense contractors to meet specific cybersecurity standards, including secure disposal of IT assets containing Controlled Unclassified Information (CUI).

Controlled Unclassified Information (CUI)

Information the U.S. government creates or possesses that requires safeguarding per law, regulation, or government-wide policy. ITAD of CUI-bearing media requires CMMC-compliant data destruction.

Cryptographic Erasure

A NIST 800-88 Purge method that destroys the encryption key for a self-encrypting drive (SED), rendering all encrypted data permanently inaccessible. Applicable to SEDs, NVMe drives with hardware encryption, and cloud storage.

D

Data Destruction

The process of permanently eliminating data from storage media using certified methods that prevent any possibility of data recovery. Methods include software overwriting, cryptographic erasure, degaussing, and physical shredding.

Data Sanitization

The broader process of permanently and irrecoverably removing data from storage media. NIST 800-88 defines three sanitization methods: Clear, Purge, and Destroy.

Data Wiping

A software-based data sanitization method that overwrites all data on a storage device with random patterns, making the original data unrecoverable while leaving the device physically intact. Also called data erasure.

Degaussing

The process of exposing magnetic storage media to a powerful alternating magnetic field that permanently erases all data by randomizing magnetic domains. Approved by the NSA for classified data destruction on HDDs and magnetic tape. Not effective on SSDs or NVMe drives.

Destroy (NIST 800-88)

The highest of three NIST 800-88 sanitization methods, involving physical destruction of the media through shredding, disintegration, or incineration. Recommended for the highest security classification levels.

DoD 5220.22-M

A U.S. Department of Defense data sanitization standard specifying a multi-pass overwrite method for clearing classified data from magnetic storage media. Largely superseded by NIST 800-88 for most applications.

Downstream Recycler

A certified facility that processes shredded or disassembled electronic components into raw materials for reuse. R2v3 certified ITAD providers must verify that all downstream recyclers meet equivalent environmental and data security standards.

E

E-Stewards

An electronics recycling certification administered by the Basel Action Network (BAN) that prohibits export of e-waste to developing countries and has strict restrictions on prison labor. An alternative to R2 certification.

E-Waste (Electronic Waste)

Any discarded electronic device or component, including computers, laptops, servers, mobile phones, tablets, televisions, printers, and networking equipment. E-waste is the world's fastest-growing waste stream.

End-of-Life (EOL)

The point at which a manufacturer ceases to provide updates, patches, or support for a product. EOL equipment should be processed through a certified ITAD provider to ensure data security and environmental compliance.

ePHI (Electronic Protected Health Information)

Any individually identifiable health information stored or transmitted in electronic form. HIPAA requires that ePHI be rendered unrecoverable when media is retired or repurposed.

ESG (Environmental, Social, and Governance)

A framework for evaluating a company's sustainability and ethical impact. ITAD providers support ESG goals through zero-landfill recycling, carbon savings reporting, and responsible downstream processing.

F

FERPA (Family Educational Rights and Privacy Act)

A U.S. federal law protecting the privacy of student education records. FERPA-compliant ITAD requires certified destruction of all student data on electronic media.

FISMA (Federal Information Security Management Act)

A U.S. federal law requiring federal agencies to develop, document, and implement information security programs, including secure disposal of IT assets.

G

GLBA (Gramm-Leach-Bliley Act)

A U.S. federal law requiring financial institutions to protect customer financial information, including secure disposal of customer data on retired media.

H

Hard Drive Shredding

The physical destruction of hard disk drives using an industrial shredder that reduces the drive to small metal particles, making data recovery impossible. Approved by the NSA for classified data destruction.

HIPAA (Health Insurance Portability and Accountability Act)

A U.S. federal law requiring healthcare organizations to protect patient health information, including certified destruction of ePHI on retired electronic media.

I

i-SIGMA

The trade association that administers NAID AAA certification for data destruction service providers. Formerly known as NAID (National Association for Information Destruction).

ISO 14001

The international standard for environmental management systems. ISO 14001 certified ITAD providers have implemented systematic processes to minimize environmental impact, including zero-landfill recycling.

ISO 27001

The international standard for information security management systems (ISMS). ISO 27001 certified ITAD providers have implemented comprehensive controls for data handling, access, and secure disposal.

ISO 9001

The international standard for quality management systems. ISO 9001 certified ITAD providers have implemented systematic quality controls across all service processes.

ITAR (International Traffic in Arms Regulations)

U.S. regulations controlling the export of defense and military-related technologies. ITAR-compliant ITAD ensures that defense-related IT equipment is disposed of domestically with certified data destruction.

ITAD (IT Asset Disposition)

The systematic, secure process of retiring end-of-life technology equipment while maximizing data security, environmental compliance, and financial value recovery. Encompasses data destruction, asset remarketing, electronics recycling, and compliance documentation.

L

Lifecycle Management

See IT Asset Lifecycle Management.

M

Media Sanitization

See Data Sanitization.

N

NAID AAA Certification

The highest standard for data destruction service providers, administered by i-SIGMA. NAID AAA certified providers undergo unannounced audits to verify data destruction processes, security protocols, and documentation.

NERC CIP

North American Electric Reliability Corporation Critical Infrastructure Protection standards requiring energy companies to protect critical infrastructure data, including secure disposal of IT assets.

NIST 800-88

NIST Special Publication 800-88, "Guidelines for Media Sanitization," the gold standard for data destruction compliance. Defines three sanitization methods: Clear, Purge, and Destroy.

NVMe (Non-Volatile Memory Express)

A high-speed storage interface protocol used in modern SSDs. NVMe drives require specific NIST 800-88 Purge methods (cryptographic erasure or firmware-level secure erase) for certified data destruction.

O

Onsite Data Destruction

Data destruction performed at the client's location using a mobile shredding or degaussing unit, eliminating chain-of-custody risk by destroying media before it leaves the client's facility.

P

PCI-DSS (Payment Card Industry Data Security Standard)

A security standard requiring organizations that process payment card data to protect cardholder information, including certified destruction of media containing cardholder data.

Purge (NIST 800-88)

The middle of three NIST 800-88 sanitization methods, using cryptographic erasure, firmware-level secure erase, or degaussing to render data unrecoverable even with laboratory techniques. Suitable for media being reused outside the organization.

R

R2v3 (Responsible Recycling version 3)

The leading international certification standard for responsible electronics recycling, requiring certified facilities to meet strict standards for data security, environmental compliance, worker health and safety, and downstream material management.

Remarketing

The process of refurbishing, certifying, and reselling used IT equipment through secondary market channels to extend hardware lifecycle and recover financial value.

Revenue Share

An ITAD arrangement where the provider and client split the proceeds from remarketed IT equipment according to a pre-agreed percentage.

S

Secure Erase

A firmware-level data sanitization command built into ATA and NVMe drives that overwrites all data on the drive using the drive's own internal processes. Qualifies as a NIST 800-88 Purge method for most drive types.

Self-Encrypting Drive (SED)

A storage device with built-in hardware encryption. SEDs can be sanitized via cryptographic erasure (destroying the encryption key), which qualifies as a NIST 800-88 Purge method.

SOX (Sarbanes-Oxley Act)

A U.S. federal law requiring public companies to maintain accurate financial records and protect financial data, including certified destruction of financial data on retired media.

T

Tape Destruction

The physical destruction or degaussing of magnetic tape media to permanently erase data. Tape destruction is required for LTO, DLT, and other enterprise backup tape formats.

U

Upstream Recycler

See ITAD Provider.

V

Value Recovery

The process of extracting financial return from retired IT equipment through certified refurbishment and remarketing. Value recovery offsets ITAD costs and can generate significant revenue for organizations with large IT refresh cycles.

W

Witnessed Destruction

A data destruction service where a client representative observes the physical destruction of their data-bearing devices in real time, providing the highest level of assurance that sensitive data has been irrecoverably destroyed.

Z

Zero Landfill

A commitment by an ITAD or recycling provider that no electronic waste from their operations will be sent to a landfill. All materials are either remarketed, refurbished, or processed through certified downstream recyclers.

Need Help Understanding ITAD Compliance?

Our certified ITAD experts can walk you through the standards, certifications, and destruction methods that matter for your industry.