Skip to content

Evidence request lists

NIST SP 800-88

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cloud and Hosted Storage Scope

NISTSP88-8
Cloud-Resident Data, Hosted Storage, and Scope Boundaries

Address cloud-resident data and hosted storage scope per NIST SP 800-88 Rev 1 considerations (acknowledged in Section 3.6) + cloud-era guidance from NIST CSF 2.0 + NIST SP 800-145 + provider-specific documentation. Cloud-resident data sanitization considerations: (a) sanitization of cloud data primarily relies on provider cryptographic erase + multi-tenant isolation + provider sanitization procedures for decommissioned drives + with consumer key control for BYOK scenarios providing the strongest consumer-side guarantee, (b) ephemeral and copy-on-write storage creates undetected copies that may persist beyond consumer-initiated deletion (snapshots + backups + replication targets + cross-region copies) so consumer must enumerate all storage targets at decommissioning, (c) provider Service Level Agreements must specify sanitization commitments + retention windows + verification mechanisms +

Artefacts an auditor will ask for
  • scope documentation per cloud service (consumer-controlled vs provider-controlled sanitization)
  • enumeration of all storage targets at decommissioning (snapshots + backups + replication + cross-region)
  • provider SLA + sanitization commitments + retention windows + provider Certificate of Sanitization equivalent
  • BYOK + consumer key destruction evidence where applicable
  • residual risk acceptance for multi-tenant sanitization where standard offering insufficient
Where this commonly fails
  • snapshots + backups overlooked at decommissioning
  • no documented scope between consumer and provider responsibilities
  • BYOK considered but not implemented for sensitive data classifications

Cryptographic Erase + Key Management

NISTSP88-4
Cryptographic Erase, Key Management, and Verification of Erase

Implement Cryptographic Erase (CE) per NIST SP 800-88 Rev 1 Section 2.5.2 + Appendix A as a Purge method where applicable. CE prerequisites per Section 2.5.2: (a) data has been encrypted from the moment of first write to the storage + or all data has been read and re-written through the encryption layer, (b) the encryption implementation is sufficiently strong (AES-128 or AES-256 with proper mode + key strength + key management), (c) all instances of the data encryption key are destroyed including backups + key escrow + recovery copies + hardware security module copies, (d) sanitization of the data encryption key is verified. Key management for CE must include (a) key inventory mapping keys to data and media + (b) controlled key generation + storage + use + (c) tamper-evident key destruction procedures per FIPS 140 validated cryptographic module where possible + (d) audit trail of key de

Artefacts an auditor will ask for
  • key inventory mapping keys to data and media
  • key destruction log linked to media sanitization log
  • encryption history per media (when encryption was enabled)
  • verification methodology per Clear / Purge / Destroy with sample size + result
Where this commonly fails
  • CE relied on without verified key destruction
  • no key inventory linking keys to media
  • verification methodology undocumented producing un-defensible sanitization

Inventory, Tracking, Chain of Custody

NISTSP88-5
Media Inventory, Tracking, Chain of Custody, and Sanitization Records

Maintain media inventory and tracking per NIST SP 800-88 Rev 1 Chapter 3 (Information Sanitization Process) + Chapter 4 (Decision Flow). Inventory must (a) track every piece of storage media from acquisition through sanitization or destruction, (b) record media type + serial number + system assignment + security categorization + data classification + location + ownership, (c) tag media at acquisition to enable lifecycle tracking, (d) interface with property management + IT asset management + records management + procurement systems. Chain of Custody per Section 3.4 must (a) document transfer of media between custodians at every step (system owner to sanitization personnel to disposal vendor to disposition), (b) record handler identity + date + time + purpose + receiving party + verification of integrity, (c) survive across organisational boundaries (when media leaves the organisation) wi

Artefacts an auditor will ask for
  • media inventory with serial + system + classification + custodian + location
  • chain of custody records for every transfer between custodians
  • Certificate of Sanitization per SP 800-88 Appendix G for every sanitization event
  • record retention policy + log retention evidence (minimum 3 years typical)
Where this commonly fails
  • inventory missing pre-decommission media
  • chain of custody broken when media leaves organisation
  • no Certificate of Sanitization or incomplete records

Media-Type Sanitization Procedures

NISTSP88-3
Media-Type Sanitization: Magnetic, SSD, Optical, Mobile, Network, Embedded

Apply media-type-specific sanitization procedures per NIST SP 800-88 Rev 1 Appendix A (Minimum Sanitization Recommendations). Magnetic Hard Disk Drives (HDD): overwrite + degauss + destroy per Section A.5 + Table A-5. Solid State Drives (SSD) and other Flash media: cryptographic erase + ATA Sanitize or vendor-specific sanitize command + destroy per Section A.7 + Table A-6 (note: simple overwrite is insufficient for SSDs due to wear-levelling and over-provisioning). Optical Media (CD + DVD + Blu-ray): destroy per Section A.10 + Table A-9 (overwrite and degauss are not applicable). Mobile Devices (smartphones + tablets): factory reset + cryptographic erase + manufacturer-specific procedures + destroy per Section A.9. Network Devices (routers + switches + firewalls): clear / reset to factory defaults + remove and sanitize storage + destroy per Section A.11. Embedded Storage in copiers + pri

Artefacts an auditor will ask for
  • sanitization procedure per media type aligned to SP 800-88 Appendix A Minimum Sanitization Recommendations
  • SSD-specific procedure using ATA Sanitize or cryptographic erase (not simple overwrite)
  • mobile device procedure aligned to vendor guidance
  • embedded storage procedure for copiers + multifunction devices + medical / ICS equipment
Where this commonly fails
  • SSD sanitised via simple overwrite (insufficient)
  • embedded storage in MFP / medical / OT devices never considered
  • mobile device factory reset accepted without verification

Policy, Roles, Decision Framework

NISTSP88-1
Media Sanitization Policy, Roles, and Decision Framework

Establish media sanitization policy per NIST SP 800-88 Rev 1 Chapter 4 (Information Sanitization and Disposition Decision Flow). Policy must (a) define the scope of media covered (electronic storage media + paper + microform + cloud-resident data + ephemeral storage), (b) name accountable roles per Chapter 3 (Information Sanitization and Decisionmaking Process): Information Owner + System Owner + Information System Security Officer + Property Custodian + Media Sanitization Personnel + Security Officer + Security Compliance Officer + Records Officer + General Counsel, (c) establish the sanitization decision flow per Section 4.5 considering Security Categorization (Confidential / Moderate / High per FIPS 199) + intended disposition (re-use within control / re-use leaving control / not re-used) + media type characteristics, (d) define sanitization method categories (Clear + Purge + Destroy)

Artefacts an auditor will ask for
  • approved media sanitization policy covering scope + decision flow per security category and disposition path
  • named roles (Information Owner + System Owner + ISSO + Property Custodian + Sanitization Personnel + Records Officer + General Counsel)
  • decision flowchart aligned to FIPS 199 + media type + disposition + Clear/Purge/Destroy method per case
  • annual policy review evidence
Where this commonly fails
  • policy generic across media types and security categories
  • no documented decision flow producing improvised choices
  • named roles in policy not implemented in operations

Sanitization Methods - Clear/Purge/Destroy

NISTSP88-2
Sanitization Method Categories: Clear, Purge, Destroy

Apply the three NIST SP 800-88 Rev 1 sanitization method categories per Chapter 2 (Background) Section 2.5. Clear (Section 2.5.1): applies logical techniques to sanitize data in all user-addressable storage locations for protection against simple non-invasive data recovery techniques + typically applied through standard read and write commands + appropriate for media that will be re-used within an organisation with consistent access controls. Purge (Section 2.5.2): applies physical or logical techniques that render Target Data recovery infeasible using state-of-the-art laboratory techniques + appropriate for media leaving organisational control such as transfer + donation + or resale + methods include cryptographic erase + degaussing (magnetic only) + overwrite with multiple patterns (specific drive capabilities) + ATA Secure Erase + ATA Sanitize. Destroy (Section 2.5.3): renders Target

Artefacts an auditor will ask for
  • documented Clear / Purge / Destroy procedures per applicable media type
  • evidence of method selection rationale per disposition
  • cryptographic erase verification (where applicable) including encryption history
Where this commonly fails
  • Clear used on media leaving organisation (should be Purge or Destroy)
  • Destroy used universally inflating cost and sustainability impact
  • Cryptographic Erase relied on without verifying encryption was enabled from first write

Third-Party Providers

NISTSP88-6
Third-Party Sanitization Providers and Vendor Qualification

Manage third-party sanitization providers per NIST SP 800-88 Rev 1 Chapter 3 Section 3.5 + Section 4.6.4. Third-party providers used for sanitization (on-site or off-site destruction services + decommissioning vendors + IT asset disposition firms) must be qualified covering (a) capability to perform required sanitization methods per Section 2.5 with documented procedures + equipment + personnel training, (b) certifications and standards (NAID AAA Certification + R2 / R2v3 Responsible Recycling + e-Stewards + ISO/IEC 27001 + sector-specific), (c) information security controls applied to media in transit and at vendor facility, (d) chain of custody procedures documented and auditable, (e) sub-contractor management with flow-down of all requirements, (f) liability insurance + indemnification + breach notification clauses in contract. Vendor performance must be monitored via (a) periodic aud

Artefacts an auditor will ask for
  • vendor qualification records (NAID AAA / R2 / e-Stewards / ISO 27001)
  • executed contracts with chain of custody + breach notification + sub-contractor flow-down + insurance clauses
  • vendor Certificate of Sanitization per batch
  • vendor audit + site visit + performance monitoring records
Where this commonly fails
  • vendor selected on cost without qualification review
  • no audit or site visit of vendor facility
  • sub-contractor flow-down not verified

Verification + Audit + Training + Safety

NISTSP88-7
Verification, Audit, Training, and Environmental/Safety Controls

Operate verification + audit + training + environmental controls per NIST SP 800-88 Rev 1 Chapter 4 Section 4.7 + Chapter 5. Verification per Section 4.7: (a) Clear verification via representative sampling and read-back testing, (b) Purge verification via sampling and laboratory verification techniques where stakes warrant, (c) Destroy verification via visual inspection + chain-of-custody documentation + photographic evidence where appropriate, (d) document verification methodology + sampling rationale + verification results per sanitization batch. Audit and continuous improvement: (a) periodic internal audit of sanitization program per Chapter 5, (b) review of Certificate of Sanitization records for completeness + accuracy + consistency, (c) trend analysis on sanitization volume + method distribution + verification failure rate + vendor performance, (d) external audit by regulator or in

Artefacts an auditor will ask for
  • verification methodology + sampling + results per sanitization batch
  • internal audit of sanitization program with trend analysis
  • personnel training records (initial + annual refresher + role-specific)
  • environmental and safety controls (OSHA + PPE + ventilation + waste handling)
Where this commonly fails
  • verification skipped to save cost
  • no internal audit of sanitization
  • training records absent for ITAD vendor managers
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-88 framework page.