Skip to content

Evidence request lists

NIST SP 800-88 Rev 1

Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Clear

MS-CLEAR-1
Clear Sanitization for Logical Reuse

Clear applies logical techniques (typically overwriting user-addressable storage) to protect against simple non-invasive recovery using standard system tools. Suitable for media reused within the organization at the same data sensitivity level.

Artefacts an auditor will ask for
  • Clear procedure documentation
  • Approved overwrite tool list
  • Single-pass overwrite logs
  • Reset-to-factory configuration records
Where this commonly fails
  • File deletion mistaken for Clear
  • Quick format used instead of full overwrite
  • Hidden areas (HPA, DCO) not addressed
MS-CLEAR-2
Clear for ATA Hard Disk Drives

For ATA HDDs, Clear is achieved by overwriting all user-addressable locations with a fixed pattern (e.g., binary zeros). A single overwrite pass is sufficient on modern drives.

Artefacts an auditor will ask for
  • Overwrite tool output logs
  • Tool validation records
  • Drive serial number to log mapping
Where this commonly fails
  • Multiple passes assumed required (myth)
  • HPA/DCO not removed before overwrite
  • Bad sectors not noted as residual risk
MS-CLEAR-3
Clear for Solid State Drives

For SSDs, Clear via overwrite is not reliable due to wear leveling and over-provisioning. Manufacturer reset commands may be used but Purge methods are preferred where confidentiality is Moderate or above.

Artefacts an auditor will ask for
  • SSD identification records
  • Justification when Clear chosen over Purge
  • Vendor command reference documentation
Where this commonly fails
  • Treating SSDs as HDDs
  • Over-reliance on overwrite on flash media
  • No detection of SSD vs HDD in workflow

Decision Framework

MS-DECISION-1
Sanitization Decision Framework

Organizations must determine the appropriate sanitization method based on data confidentiality (Low, Moderate, High), security categorization per FIPS 199, and whether the media will be reused internally, transferred externally, or destroyed.

Artefacts an auditor will ask for
  • Media sanitization policy
  • Data classification mapping to sanitization method
  • Decision flowchart referencing Figure 4-1
  • FIPS 199 categorization records
Where this commonly fails
  • No documented link between data sensitivity and sanitization method
  • Decision left to individual technicians
  • No reuse-vs-disposal pathway defined
MS-DECISION-2
Media Inventory and Tracking

All storage media must be inventoried with type, serial number, classification of data stored, custodian, and disposition status tracked through sanitization to final disposition.

Artefacts an auditor will ask for
  • Media inventory register
  • Asset tags or serial number records
  • Chain of custody logs
  • Media movement records
Where this commonly fails
  • Loose media not tagged
  • No tracking of embedded storage in printers, MFPs, networking gear
  • Lost media not detected until audit
MS-DECISION-3
Roles and Responsibilities

Defined roles must include Program Manager, Information System Owner, Information System Security Officer, Property Management Officer, Records Management Officer, and Users, each with documented sanitization responsibilities.

Artefacts an auditor will ask for
  • RACI matrix for media sanitization
  • Job descriptions referencing sanitization duties
  • Delegation of authority memos
Where this commonly fails
  • No named accountable owner
  • IT operates without security oversight
  • No records management role for retention conflicts

Destroy

MS-DESTROY-1
Destroy as Highest Sanitization Level

Destroy renders target data recovery infeasible and the media unable to be reused. Methods include disintegration, pulverization, melting, incineration, and shredding to particle sizes appropriate for the media.

Artefacts an auditor will ask for
  • Destruction procedure
  • Particle size specification per media type
  • Destruction equipment certification
  • Photo and video evidence where required
Where this commonly fails
  • Drilling holes treated as destruction (insufficient for flash)
  • Shred size too large for SSDs
  • No witness of destruction
MS-DESTROY-2
Shredding Particle Size for SSDs and Flash

SSDs and flash media require finer shred particle sizes than HDDs because individual memory chips can retain data. Shredding must produce particles small enough to disrupt NAND flash packages.

Artefacts an auditor will ask for
  • Shredder specification sheet
  • Particle size sampling photographs
  • Vendor compliance statement against 800-88
Where this commonly fails
  • HDD shredder used on SSDs
  • Particle size never measured
  • Chips visually intact post-shred
MS-DESTROY-3
Optical Media Destruction

CDs, DVDs, and Blu-ray discs are sanitized by destruction only (shredding, disintegration, or incineration). Overwriting and degaussing are not effective.

Artefacts an auditor will ask for
  • Optical media destruction logs
  • Approved optical shredder records
  • Particle size verification
Where this commonly fails
  • Optical discs scratched only
  • Discs binned with general waste
  • Archive discs forgotten in safes
MS-DESTROY-4
Paper and Microform Destruction

Paper records and microforms (microfilm, microfiche) are sanitized by destruction methods such as cross-cut shredding, pulping, pulverization, or incineration to specified particle sizes.

Artefacts an auditor will ask for
  • Cross-cut shredder specification (particle size <= 1mm x 5mm for high sensitivity)
  • Pulping vendor contract
  • Destruction certificates
Where this commonly fails
  • Strip-cut shredders used for sensitive data
  • Locked bins not collected for weeks
  • Microforms missed in destruction workflow
MS-DESTROY-5
Embedded Storage in Peripherals

Multifunction devices, printers, copiers, fax machines, and scanners often contain hard drives or flash storing scanned and printed content. These must be sanitized using device-specific methods before disposal.

Artefacts an auditor will ask for
  • MFP sanitization SOP
  • Vendor-provided sanitize utility records
  • Lease return sanitization confirmation
Where this commonly fails
  • Leased MFPs returned without sanitization
  • Internal drives not inventoried
  • Vendor sanitize feature never enabled
MS-DESTROY-6
Networking Equipment Sanitization

Routers, switches, firewalls, and load balancers store configuration, credentials, certificates, and cached data. Sanitization requires vendor-specific factory reset combined with credential and certificate removal, or physical destruction.

Artefacts an auditor will ask for
  • Per-vendor sanitization runbook
  • Configuration wipe logs
  • Certificate revocation records
Where this commonly fails
  • Factory reset only (config left in flash slot)
  • RMA returns with credentials intact
  • Bootloader configs retained
MS-DESTROY-7
Mobile Devices and Tablets

Mobile devices are sanitized by performing a manufacturer factory reset on encrypted devices (cryptographic erase equivalent) and removing SIM and SD cards, or by physical destruction for high sensitivity.

Artefacts an auditor will ask for
  • MDM-enforced encryption records
  • Factory reset logs from MDM
  • SIM and SD removal procedure
Where this commonly fails
  • Reset performed on unencrypted devices
  • External SD cards left in
  • BYOD devices never sanitized on offboarding
MS-DESTROY-8
IoT and Embedded Systems

IoT devices, embedded controllers, and appliances often contain flash storage with credentials and operational data. Where sanitize commands are not provided, physical destruction of the storage component is required.

Artefacts an auditor will ask for
  • IoT device inventory
  • Component-level destruction records
  • Vendor disposal guidance review
Where this commonly fails
  • IoT excluded from media sanitization scope
  • Decommissioned devices stored indefinitely
  • Cameras and sensors discarded with config intact

Documentation

MS-DOC-1
Certificate of Sanitization

Each sanitization action is documented in a Certificate of Sanitization recording media identifiers, method used, tool version, operator, verifier, date, and final disposition. Appendix G provides a sample template.

Artefacts an auditor will ask for
  • Completed Certificates of Sanitization
  • Index linking certificate to asset record
  • Retention schedule for certificates
Where this commonly fails
  • No certificate produced
  • Certificate lacks tool version or verifier
  • Certificates retained shorter than asset record
MS-DOC-2
Third-Party Sanitization Vendor Oversight

When sanitization is outsourced, contracts must require 800-88 conformance, define media types in scope, require Certificates of Sanitization, allow audits, and specify chain of custody.

Artefacts an auditor will ask for
  • Vendor contract clauses citing 800-88
  • Audit reports of vendor facility
  • Per-shipment chain of custody and certificates
  • Vendor certifications (e.g., NAID AAA where used)
Where this commonly fails
  • Vendor selected on price without 800-88 reference
  • No right-to-audit clause
  • Certificates accepted unread
MS-DOC-3
Records Retention

Sanitization records must be retained according to organizational and regulatory schedules, typically for the lifetime of the asset record plus a defined period to support audit and incident investigation.

Artefacts an auditor will ask for
  • Retention schedule covering sanitization records
  • Archive of certificates
  • Destruction of records only per schedule
Where this commonly fails
  • Certificates destroyed at end of year
  • No mapping to asset disposal
  • Records stored only in operator email

Purge

MS-PURGE-1
Purge Sanitization for External Release

Purge applies physical or logical techniques that render target data recovery infeasible using state of the art laboratory techniques. Required for media leaving organizational control at Moderate or higher confidentiality.

Artefacts an auditor will ask for
  • Purge procedure
  • Cryptographic Erase, Secure Erase, or Sanitize command logs
  • Degaussing equipment records (magnetic media only)
Where this commonly fails
  • Clear used where Purge required
  • No verification step
  • Degaussing applied to SSDs (ineffective)
MS-PURGE-2
ATA Secure Erase and Sanitize Commands

For ATA drives, Purge uses the SECURITY ERASE UNIT command (Secure Erase) or the SANITIZE DEVICE feature set (block erase, crypto scramble, overwrite). The sanitize feature set is preferred where available.

Artefacts an auditor will ask for
  • Sanitize command output
  • Drive firmware support verification
  • Command completion confirmation logs
Where this commonly fails
  • Command issued but completion not verified
  • Frozen drive state not unfrozen before command
  • Firmware does not actually implement command
MS-PURGE-3
SCSI Sanitize for Enterprise Drives

SCSI drives are purged using the SANITIZE command set (overwrite, block erase, crypto erase, exit failure mode). Format Unit alone is not a Purge equivalent.

Artefacts an auditor will ask for
  • SCSI sanitize logs
  • Drive type identification
  • Tool that issues correct opcode (not just format)
Where this commonly fails
  • Format Unit treated as Purge
  • Vendor utility outputs not captured
  • RAID controllers blocking direct command
MS-PURGE-4
NVMe Sanitize and Format

NVMe drives use the Sanitize command (block erase, crypto erase, overwrite) or Format NVM with Secure Erase setting. Crypto erase is the fastest method when supported.

Artefacts an auditor will ask for
  • NVMe sanitize log output
  • Controller capability identify records
  • Completion status records
Where this commonly fails
  • Format NVM run without secure erase setting
  • Namespace not fully cleared
  • Sanitize aborted by host reset
MS-PURGE-5
Cryptographic Erase

Cryptographic Erase (CE) sanitizes media by deleting or replacing the media encryption key used by self-encrypting drives, rendering ciphertext unrecoverable. Requires that all target data was encrypted before storage and the key destruction is verified.

Artefacts an auditor will ask for
  • Self-encrypting drive (SED) inventory
  • Key destruction logs
  • Evidence encryption was enabled from first write
  • Vendor CE attestation
Where this commonly fails
  • CE used on drives that stored cleartext before encryption was enabled
  • Backup copies of key not destroyed
  • Key escrow not addressed
MS-PURGE-6
Degaussing of Magnetic Media

Degaussing exposes magnetic media to a strong magnetic field, rendering it unreadable. The degausser must be rated for the media coercivity. Degaussing renders most drives non-functional and does not work on SSDs or flash.

Artefacts an auditor will ask for
  • Degausser NSA EPL listing or coercivity rating
  • Degausser maintenance and calibration records
  • Operator training records
  • Drive serial to cycle log
Where this commonly fails
  • Degausser coercivity below drive rating
  • SSDs degaussed (ineffective)
  • No periodic field strength verification
MS-PURGE-7
Magnetic Tape Sanitization

Magnetic tapes are purged by degaussing with an appropriately rated degausser or by destruction. Overwriting tapes is permitted as Clear only and is not reliable for Purge.

Artefacts an auditor will ask for
  • Tape inventory
  • Degausser rating vs tape generation matrix
  • Backup tape rotation and sanitization records
Where this commonly fails
  • LTO tape degaussed with HDD-rated degausser
  • Tapes overwritten and released externally
  • Offsite backup vendor process not verified
MS-PURGE-8
Flash Memory (USB, SD, eMMC) Purge

Removable flash media (USB drives, SD cards, eMMC) typically lack standardized purge commands. Where vendor sanitize is unavailable, destruction is required for Purge equivalence.

Artefacts an auditor will ask for
  • Flash device inventory
  • Vendor sanitize support records
  • Destruction logs where commands unavailable
Where this commonly fails
  • USB sticks formatted and reused externally
  • SD cards in cameras and phones overlooked
  • eMMC on embedded boards forgotten

Verification

MS-VERIFY-1
Verification of Sanitization

Every sanitization action must be verified. Verification confirms the selected method was correctly applied and that residual data is not recoverable using methods commensurate with the sanitization category.

Artefacts an auditor will ask for
  • Verification procedure
  • Sample-based readback or destruction inspection
  • Independent verifier records
Where this commonly fails
  • No verification step
  • Same operator performs and verifies (no separation)
  • Verification skipped for Destroy when visual check claimed
MS-VERIFY-2
Full vs Representative Sampling

Full verification reads all addressable locations to confirm sanitization. Where full verification is impractical (e.g., large volume Destroy), representative sampling per a documented sampling plan is acceptable.

Artefacts an auditor will ask for
  • Sampling plan with sample size justification
  • Sample selection records (random)
  • Sample inspection results
Where this commonly fails
  • Sampling rate not defined
  • Same samples picked each batch
  • Sampling used where full verification was practical
MS-VERIFY-3
Equipment Testing and Calibration

Sanitization equipment (degaussers, shredders, sanitize utilities) must be tested at acquisition, periodically thereafter, and after maintenance to confirm continued effectiveness.

Artefacts an auditor will ask for
  • Equipment acquisition test records
  • Annual or periodic test schedule
  • Post-maintenance test results
Where this commonly fails
  • Equipment never retested after purchase
  • Field strength of degausser unmeasured
  • Software tool versions not tracked
MS-VERIFY-4
Personnel Competency

Personnel performing sanitization must have documented training appropriate to media types and methods used. Competency is reassessed when procedures or technology change.

Artefacts an auditor will ask for
  • Training records per operator
  • Competency assessment
  • Refresher schedule
Where this commonly fails
  • Operators trained once at hire only
  • Training does not cover new media types (NVMe, SED)
  • Third-party vendor staff competency unverified
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.