Secure data wiping and physical media destruction are different risk treatments, and the right choice depends on the media, information sensitivity, intended reuse and your organisation’s policy. Destroying every drive can be unnecessary when trusted sanitisation enables safe reuse, while wiping is not appropriate when media is failed, unsupported or policy requires physical destruction.
Current NIST SP 800-88 Rev. 2 guidance places the decision inside a formal media sanitisation program rather than prescribing one universal method for every device.
Data wiping is a form of logical sanitisation that uses an approved technique to render target data inaccessible while keeping the storage media usable. Depending on the media, risk and technique, this may support a NIST Clear or Purge outcome.
Modern sanitisation is not simply a matter of choosing a fixed number of overwrite passes. SSDs, NVMe devices, encrypted storage and other media can require different trusted techniques. NIST Rev. 2 therefore points organisations toward current standards such as IEEE 2883, applicable NSA specifications or another organisationally approved standard, rather than maintaining a large list of device-specific instructions.
Physical destruction renders storage media unusable so that recovery of target data is infeasible. Depending on the media and required outcome, this can involve appropriate shredding, crushing, disintegration or other approved destruction processes.
Destruction is often appropriate for failed or damaged media that cannot be reliably sanitised, unsupported media, very high-risk information, or situations where organisational policy specifically requires destruction.
Secure sanitisation can be preferable when equipment is functional, supported by an appropriate trusted technique and suitable for reuse, redeployment, refurbishment or resale. Advantages can include:
The key is assurance: the selected sanitisation technique must be appropriate for the exact media and the result should be verified and documented.
Physical destruction is commonly considered when:
Not necessarily. Security depends on using an appropriate process and achieving the required outcome. A poorly controlled destruction process can have chain-of-custody or particle-size issues, just as an unsuitable wiping method can fail to sanitise data correctly.
The stronger approach is to define approved decision rules, maintain custody of the asset, use a suitable technique, verify the result and retain evidence.
Cryptographic erase can provide an efficient sanitisation technique when its prerequisites are satisfied. Rev. 2 expands guidance around cryptographic erase and key sanitisation, but it should not be assumed to work safely in every situation. The organisation needs confidence in the encryption implementation, key management and the state of the media.
Sometimes, but not automatically. If policy requires physical destruction, an additional wipe may be unnecessary. In other workflows, sanitisation may occur before equipment is assessed for reuse and assets that fail the process are then routed to destruction. The correct workflow should be documented in the organisation’s sanitisation policy and project scope.
Whether equipment is sanitised or destroyed, the evidence should allow you to reconcile the outcome with the original asset. Useful records can include serial number or asset identifier, media details, selected method, processing result, timestamps, verification or validation information where applicable, and the final disposition.
Recycle IT’s audit reporting and secure data sanitisation and destruction services are designed to support an auditable IT asset retirement process.
A practical decision starts with four questions:
For a broader explanation of the current guidance, read NIST SP 800-88 Rev. 2: What Changed for IT Asset Disposal.
Request a quote to discuss the appropriate handling and reporting requirements for your IT assets.
This article provides general information. Sanitisation and destruction decisions should follow your organisation’s approved policies, risk assessment and applicable requirements.