NIST SP 800-88 Rev 1
Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Clear
Clear applies logical techniques (typically overwriting user-addressable storage) to protect against simple non-invasive recovery using standard system tools. Suitable for media reused within the organization at the same data sensitivity level.
- Clear procedure documentation
- Approved overwrite tool list
- Single-pass overwrite logs
- Reset-to-factory configuration records
- File deletion mistaken for Clear
- Quick format used instead of full overwrite
- Hidden areas (HPA, DCO) not addressed
For ATA HDDs, Clear is achieved by overwriting all user-addressable locations with a fixed pattern (e.g., binary zeros). A single overwrite pass is sufficient on modern drives.
- Overwrite tool output logs
- Tool validation records
- Drive serial number to log mapping
- Multiple passes assumed required (myth)
- HPA/DCO not removed before overwrite
- Bad sectors not noted as residual risk
For SSDs, Clear via overwrite is not reliable due to wear leveling and over-provisioning. Manufacturer reset commands may be used but Purge methods are preferred where confidentiality is Moderate or above.
- SSD identification records
- Justification when Clear chosen over Purge
- Vendor command reference documentation
- Treating SSDs as HDDs
- Over-reliance on overwrite on flash media
- No detection of SSD vs HDD in workflow
Decision Framework
Organizations must determine the appropriate sanitization method based on data confidentiality (Low, Moderate, High), security categorization per FIPS 199, and whether the media will be reused internally, transferred externally, or destroyed.
- Media sanitization policy
- Data classification mapping to sanitization method
- Decision flowchart referencing Figure 4-1
- FIPS 199 categorization records
- No documented link between data sensitivity and sanitization method
- Decision left to individual technicians
- No reuse-vs-disposal pathway defined
All storage media must be inventoried with type, serial number, classification of data stored, custodian, and disposition status tracked through sanitization to final disposition.
- Media inventory register
- Asset tags or serial number records
- Chain of custody logs
- Media movement records
- Loose media not tagged
- No tracking of embedded storage in printers, MFPs, networking gear
- Lost media not detected until audit
Defined roles must include Program Manager, Information System Owner, Information System Security Officer, Property Management Officer, Records Management Officer, and Users, each with documented sanitization responsibilities.
- RACI matrix for media sanitization
- Job descriptions referencing sanitization duties
- Delegation of authority memos
- No named accountable owner
- IT operates without security oversight
- No records management role for retention conflicts
Destroy
Destroy renders target data recovery infeasible and the media unable to be reused. Methods include disintegration, pulverization, melting, incineration, and shredding to particle sizes appropriate for the media.
- Destruction procedure
- Particle size specification per media type
- Destruction equipment certification
- Photo and video evidence where required
- Drilling holes treated as destruction (insufficient for flash)
- Shred size too large for SSDs
- No witness of destruction
SSDs and flash media require finer shred particle sizes than HDDs because individual memory chips can retain data. Shredding must produce particles small enough to disrupt NAND flash packages.
- Shredder specification sheet
- Particle size sampling photographs
- Vendor compliance statement against 800-88
- HDD shredder used on SSDs
- Particle size never measured
- Chips visually intact post-shred
CDs, DVDs, and Blu-ray discs are sanitized by destruction only (shredding, disintegration, or incineration). Overwriting and degaussing are not effective.
- Optical media destruction logs
- Approved optical shredder records
- Particle size verification
- Optical discs scratched only
- Discs binned with general waste
- Archive discs forgotten in safes
Paper records and microforms (microfilm, microfiche) are sanitized by destruction methods such as cross-cut shredding, pulping, pulverization, or incineration to specified particle sizes.
- Cross-cut shredder specification (particle size <= 1mm x 5mm for high sensitivity)
- Pulping vendor contract
- Destruction certificates
- Strip-cut shredders used for sensitive data
- Locked bins not collected for weeks
- Microforms missed in destruction workflow
Multifunction devices, printers, copiers, fax machines, and scanners often contain hard drives or flash storing scanned and printed content. These must be sanitized using device-specific methods before disposal.
- MFP sanitization SOP
- Vendor-provided sanitize utility records
- Lease return sanitization confirmation
- Leased MFPs returned without sanitization
- Internal drives not inventoried
- Vendor sanitize feature never enabled
Routers, switches, firewalls, and load balancers store configuration, credentials, certificates, and cached data. Sanitization requires vendor-specific factory reset combined with credential and certificate removal, or physical destruction.
- Per-vendor sanitization runbook
- Configuration wipe logs
- Certificate revocation records
- Factory reset only (config left in flash slot)
- RMA returns with credentials intact
- Bootloader configs retained
Mobile devices are sanitized by performing a manufacturer factory reset on encrypted devices (cryptographic erase equivalent) and removing SIM and SD cards, or by physical destruction for high sensitivity.
- MDM-enforced encryption records
- Factory reset logs from MDM
- SIM and SD removal procedure
- Reset performed on unencrypted devices
- External SD cards left in
- BYOD devices never sanitized on offboarding
IoT devices, embedded controllers, and appliances often contain flash storage with credentials and operational data. Where sanitize commands are not provided, physical destruction of the storage component is required.
- IoT device inventory
- Component-level destruction records
- Vendor disposal guidance review
- IoT excluded from media sanitization scope
- Decommissioned devices stored indefinitely
- Cameras and sensors discarded with config intact
Documentation
Each sanitization action is documented in a Certificate of Sanitization recording media identifiers, method used, tool version, operator, verifier, date, and final disposition. Appendix G provides a sample template.
- Completed Certificates of Sanitization
- Index linking certificate to asset record
- Retention schedule for certificates
- No certificate produced
- Certificate lacks tool version or verifier
- Certificates retained shorter than asset record
When sanitization is outsourced, contracts must require 800-88 conformance, define media types in scope, require Certificates of Sanitization, allow audits, and specify chain of custody.
- Vendor contract clauses citing 800-88
- Audit reports of vendor facility
- Per-shipment chain of custody and certificates
- Vendor certifications (e.g., NAID AAA where used)
- Vendor selected on price without 800-88 reference
- No right-to-audit clause
- Certificates accepted unread
Sanitization records must be retained according to organizational and regulatory schedules, typically for the lifetime of the asset record plus a defined period to support audit and incident investigation.
- Retention schedule covering sanitization records
- Archive of certificates
- Destruction of records only per schedule
- Certificates destroyed at end of year
- No mapping to asset disposal
- Records stored only in operator email
Purge
Purge applies physical or logical techniques that render target data recovery infeasible using state of the art laboratory techniques. Required for media leaving organizational control at Moderate or higher confidentiality.
- Purge procedure
- Cryptographic Erase, Secure Erase, or Sanitize command logs
- Degaussing equipment records (magnetic media only)
- Clear used where Purge required
- No verification step
- Degaussing applied to SSDs (ineffective)
For ATA drives, Purge uses the SECURITY ERASE UNIT command (Secure Erase) or the SANITIZE DEVICE feature set (block erase, crypto scramble, overwrite). The sanitize feature set is preferred where available.
- Sanitize command output
- Drive firmware support verification
- Command completion confirmation logs
- Command issued but completion not verified
- Frozen drive state not unfrozen before command
- Firmware does not actually implement command
SCSI drives are purged using the SANITIZE command set (overwrite, block erase, crypto erase, exit failure mode). Format Unit alone is not a Purge equivalent.
- SCSI sanitize logs
- Drive type identification
- Tool that issues correct opcode (not just format)
- Format Unit treated as Purge
- Vendor utility outputs not captured
- RAID controllers blocking direct command
NVMe drives use the Sanitize command (block erase, crypto erase, overwrite) or Format NVM with Secure Erase setting. Crypto erase is the fastest method when supported.
- NVMe sanitize log output
- Controller capability identify records
- Completion status records
- Format NVM run without secure erase setting
- Namespace not fully cleared
- Sanitize aborted by host reset
Cryptographic Erase (CE) sanitizes media by deleting or replacing the media encryption key used by self-encrypting drives, rendering ciphertext unrecoverable. Requires that all target data was encrypted before storage and the key destruction is verified.
- Self-encrypting drive (SED) inventory
- Key destruction logs
- Evidence encryption was enabled from first write
- Vendor CE attestation
- CE used on drives that stored cleartext before encryption was enabled
- Backup copies of key not destroyed
- Key escrow not addressed
Degaussing exposes magnetic media to a strong magnetic field, rendering it unreadable. The degausser must be rated for the media coercivity. Degaussing renders most drives non-functional and does not work on SSDs or flash.
- Degausser NSA EPL listing or coercivity rating
- Degausser maintenance and calibration records
- Operator training records
- Drive serial to cycle log
- Degausser coercivity below drive rating
- SSDs degaussed (ineffective)
- No periodic field strength verification
Magnetic tapes are purged by degaussing with an appropriately rated degausser or by destruction. Overwriting tapes is permitted as Clear only and is not reliable for Purge.
- Tape inventory
- Degausser rating vs tape generation matrix
- Backup tape rotation and sanitization records
- LTO tape degaussed with HDD-rated degausser
- Tapes overwritten and released externally
- Offsite backup vendor process not verified
Removable flash media (USB drives, SD cards, eMMC) typically lack standardized purge commands. Where vendor sanitize is unavailable, destruction is required for Purge equivalence.
- Flash device inventory
- Vendor sanitize support records
- Destruction logs where commands unavailable
- USB sticks formatted and reused externally
- SD cards in cameras and phones overlooked
- eMMC on embedded boards forgotten
Verification
Every sanitization action must be verified. Verification confirms the selected method was correctly applied and that residual data is not recoverable using methods commensurate with the sanitization category.
- Verification procedure
- Sample-based readback or destruction inspection
- Independent verifier records
- No verification step
- Same operator performs and verifies (no separation)
- Verification skipped for Destroy when visual check claimed
Full verification reads all addressable locations to confirm sanitization. Where full verification is impractical (e.g., large volume Destroy), representative sampling per a documented sampling plan is acceptable.
- Sampling plan with sample size justification
- Sample selection records (random)
- Sample inspection results
- Sampling rate not defined
- Same samples picked each batch
- Sampling used where full verification was practical
Sanitization equipment (degaussers, shredders, sanitize utilities) must be tested at acquisition, periodically thereafter, and after maintenance to confirm continued effectiveness.
- Equipment acquisition test records
- Annual or periodic test schedule
- Post-maintenance test results
- Equipment never retested after purchase
- Field strength of degausser unmeasured
- Software tool versions not tracked
Personnel performing sanitization must have documented training appropriate to media types and methods used. Competency is reassessed when procedures or technology change.
- Training records per operator
- Competency assessment
- Refresher schedule
- Operators trained once at hire only
- Training does not cover new media types (NVMe, SED)
- Third-party vendor staff competency unverified
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.