Cybersecurity GRC 15 items
Media Sanitization & Secure Data Disposal (NIST 800-88)
Assesses secure media sanitization and data disposal practices using NIST SP 800-88, covering categorization, sanitization methods, verification, and certificate of destruction.
NIST 800-88NIST 800-53ISO 27001
Free PDF · enter your email to download.
Policy & Categorization
- Is a media sanitization policy documented covering all media types? *
- Is the sanitization method selected based on data confidentiality and reuse decision? *
- Is an inventory maintained of media pending sanitization or destruction? *
- Are media types and their appropriate techniques documented (HDD, SSD, tape, mobile, cloud)?
Sanitization Methods
- Is the correct level (Clear, Purge, or Destroy) applied per data sensitivity? *
- Are cryptographic-erase or purge techniques used for SSDs and self-encrypting drives? *
- Is physical destruction (shred/disintegrate/degauss) used for highest-sensitivity media?
- Is cloud/virtual data disposal addressed (crypto-erase, provider attestation)?
Verification & Documentation
- Is sanitization verified before media is released or reused? *
- Is a certificate or record of sanitization/destruction retained per asset? *
- Does the record capture media ID, method, operator, and date? *
- Is chain of custody maintained until sanitization is complete?
Third-Party Disposal
- Are third-party ITAD/disposal vendors vetted and under contract with security requirements? *
- Are certificates of destruction obtained and reconciled against the media inventory? *
- Is vendor destruction periodically audited or witnessed?
Download the full Media Sanitization & Secure Data Disposal (NIST 800-88) checklist
Get it as a clean, printable PDF — free.
