7.5 Resource & Media Protection
7.5 Resource & Media Protection
Information does not become safe simply because it is stored on an organisation's equipment.
Data may exist on servers, laptops, backup tapes, removable drives, mobile devices, cloud storage, printed documents and many other forms of media.
Security Operations must protect that information throughout its operational life - while it is stored, when it is moved and when the media is eventually reused, returned or disposed of.
Manage
Know which media exists, what it contains and how it should be handled.
KNOW THE MEDIAProtect
Apply physical, logical and cryptographic safeguards according to information sensitivity.
PROTECT THE DATASanitise
Prevent sensitive information from remaining accessible when media leaves its current use.
REMOVE THE DATA SAFELYApply Resource Protection
Control media throughout its operational lifecycle, including access, storage, handling, transport, reuse and disposal.
Apply appropriate physical, logical and cryptographic safeguards to protect information stored on media.
Protect information according to whether it is being stored or transmitted.
7.5 Official Scope
The Big Idea
Resource protection should follow the information wherever it goes.
Resource Protection Flow
What Counts as Media?
Media is anything on which information can be recorded, stored or printed.
📄 Digital & Non-Digital Media Media protection applies beyond electronic storage
A printed payroll report containing employee salary information still requires:
Media Management Lifecycle
Media Lifecycle
Media Inventory & Accountability
Sensitive media should be managed so the organisation understands what exists and who is responsible for it.
Assign an identifier where appropriate.
Establish who is responsible for its handling.
Understand the type and sensitivity of information stored.
Know where sensitive media is held.
Active, stored, transferred, retired or pending destruction.
Track important transfers where required.
🏷️ Media Marking Communicate applicable handling and distribution requirements
Media markings can help people recognise that particular handling, storage or distribution requirements apply.
Backup media containing highly sensitive information may be labelled according to the organisation's classification and handling procedures.
Labels themselves should be designed appropriately so that the marking does not unnecessarily disclose sensitive information about the contents.
Media Access
Access to sensitive media should be limited to authorised people, roles, devices and processes.
Locks, controlled rooms, secure cabinets and authorised personnel.
Authentication, access control and permissions on digital media.
Encryption can protect information if the media is lost or accessed outside authorised systems.
Check-out, return or transfer records may be appropriate for sensitive media.
Secure Media Storage
Restrict access to rooms, cabinets and storage facilities.
Protect media against temperature, humidity, water, fire and other damaging conditions where relevant.
Protect sensitive digital information against unauthorised disclosure.
Record access to highly sensitive repositories where appropriate.
Store particularly sensitive media within appropriately controlled areas.
Periodically confirm that expected media remains accounted for.
Media Transport
Physical media may need to move between offices, data centres, suppliers, backup locations or storage facilities.
Ensure movement is permitted.
Protect digital information if the media is lost or intercepted.
Use appropriate protective or tamper-evident packaging when required.
Maintain accountability for sensitive media during movement.
Use suitable transportation mechanisms according to sensitivity and policy.
Confirm that the intended recipient received the media.
Physical Media Transport
🔗 Media Tracking vs Forensic Chain of Custody Similar accountability idea - different purpose
Operational control showing where sensitive organisational media is and who possesses it.
Formal evidence-handling history used to establish the custody and handling of investigative evidence.
Removable Media
Removable media is portable and easy to connect to different systems, which makes it useful operationally but also creates security risk.
Sensitive information can be copied and physically removed.
Untrusted media can introduce malicious software.
Small portable devices are easily misplaced or stolen.
Information may be duplicated outside managed repositories.
Security teams may not know where the device has previously been connected.
Removable storage may circumvent normal network-based data controls.
🔌 USB Media Controls Allow according to business need and risk
An employee finds an unknown USB drive in the car park.
They connect it to their corporate laptop to discover:
who owns it.
Media Use Restrictions
Organisations may restrict the type of media that can be used with particular systems.
Policy:
No personally owned removable storage.
Data may be exported only to:
organisation-managed encrypted media.
Media Protection Techniques
Protect information from unauthorised disclosure if storage is accessed or lost.
Restrict who or what can use the media.
Secure media against theft, damage and unauthorised handling.
Control which portable storage devices may connect to systems.
Detect or restrict inappropriate transfer of sensitive information.
Detect inappropriate modification where required.
Prevent modification where media should be read-only.
Check removable or exchanged media before trusted use where appropriate.
Maintain recoverable copies while applying equivalent protection to the backup media.
Remove sensitive information before reuse or disposal.
Protection Follows Classification
May require: minimal confidentiality controls.
May require:
Data at Rest vs Data in Transit
Information stored on media rather than actively moving between systems.
STORED
Information being transmitted between systems, devices, networks or services.
MOVING
Data States
🧠 What About Data in Use? An important data state even though 7.5 explicitly names rest and transit
Data in use is information currently being processed or actively used by a system.
An encrypted customer database is opened by an authorised application.
The information may need to exist in usable form while:
the application processes it.
Three Data States
Protecting Data at Rest
Protect an entire storage volume against offline access.
Protect selected information.
Protect database files, tables, columns or other stored data depending on the implementation.
Protect stored cloud objects, volumes, backups and snapshots.
Restrict which identities can read or modify stored information.
Protect the storage device itself.
Protect the cryptographic keys required to decrypt the information.
Detect inappropriate access to sensitive repositories.
At Rest
💻 Full-Disk Encryption Excellent against some threats - not every threat
Disk is strongly encrypted.
Attacker removes the drive and attempts to read it.
Full-disk encryption can provide strong protection against this offline access scenario.
Operating system has already unlocked the encrypted volume.
Malware runs with the user's privileges.
Disk encryption alone may not prevent access to information already available through the running system.
Encryption Is Only as Useful as Its Key Management
Create keys appropriately.
Protect keys from unauthorised access.
Deliver keys securely when necessary.
Limit which identities and systems can use them.
Replace keys according to applicable requirements.
Remove keys when they should no longer provide access.
Protecting Data in Transit
Protect application communications such as HTTPS and other TLS-enabled services.
Protect communications at the IP layer.
Establish protected communication across untrusted networks.
Protect remote administrative communications.
Protect files while they are transferred between systems.
Verify the identity of communication endpoints where required.
Detect inappropriate modification during transmission.
Ensure encrypted communications establish trust with the intended endpoint.
In Transit
↔️ Encryption at Rest ≠ Encryption in Transit Protecting one state does not automatically protect another
Disk: encrypted.
Connection from application to database: unencrypted.
The database is protected:
while stored.
But information may be exposed:
while moving across the network.
🌐 Private Network ≠ Encrypted Network Network location and cryptographic protection are different controls
Traffic remains entirely within: the corporate data centre.
Does that automatically mean: the traffic is encrypted?
No.
Where Does Encryption Begin and End?
When evaluating data in transit, do not ask only:
"Is encryption enabled?"
Ask:
Backup Media Needs Protection Too
Backups may contain complete copies of highly sensitive production information.
Protect confidential backup contents.
Restrict who can retrieve or restore backups.
Secure backup tapes or devices.
Protect media while moving to external storage.
Protect against unauthorised modification.
Apply approved retention and disposal requirements.
🗄️ Encrypted Production ≠ Encrypted Backup Do not assume protection automatically follows the copy
Storage encryption: enabled.
Stored as: unencrypted backup file.
Printed Information
Restrict sensitive printing according to business need.
Prevent sensitive documents from being left unattended at printers.
Use appropriate locked or controlled storage.
Protect documents when moved.
Destroy sensitive paper using an appropriate method.
Confidential customer report remains:
unattended in a shared printer tray.
🖨️ The Printer May Contain Data Too Do not focus only on the printed sheet
Modern printers, scanners and multifunction devices may contain internal storage used for:
Multifunction printer is returned to supplier.
Internal storage was never: sanitised.
Media Sanitisation
Sanitisation makes access to target information on media infeasible for an appropriate level of effort.
It becomes important before media is:
Before Media Leaves
🗑️ Delete ≠ Sanitise Removing the reference to data may not remove the underlying data
Delete file.
💽 Formatting ≠ Automatically Sanitisation The method must be suitable for the media and required assurance
Reformatting or reinstalling an operating system should not automatically be treated as sufficient sanitisation for sensitive information.
Clear · Purge · Destroy
Apply logical sanitisation techniques appropriate for reuse within the intended environment and required assurance.
LOGICAL SANITISATION
Apply a stronger sanitisation process intended to make recovery infeasible even using more advanced recovery techniques.
STRONGER SANITISATION
Render the media unusable so that it cannot be used again as storage media.
MEDIA NO LONGER REUSABLE
Sanitisation
Choose the Method According to the Media
Sanitisation is not a single universal command that works equally well for every storage technology.
Requires methods appropriate to magnetic storage technology.
Requires methods appropriate to flash-memory architecture and device behaviour.
May require physical destruction where suitable logical sanitisation is unavailable.
Requires an appropriate physical destruction process.
Requires consideration of logical deletion, provider architecture, encryption keys, snapshots, backups and contractual controls.
🔑 Cryptographic Erase Render encrypted data inaccessible by sanitising the required cryptographic key material
The effectiveness of the approach depends on factors such as whether the target data was actually encrypted with suitable cryptography and whether relevant copies of the required key material remain.
Validate Sanitisation
Performing a sanitisation procedure is not the end of the process.
Organisations should obtain appropriate assurance that the selected sanitisation approach was completed effectively.
🔨 Physical Destruction Appropriate when media will not be reused and required sanitisation warrants destruction
Appropriate destruction techniques depend on the media technology and applicable organisational requirements.
Data Remanence
Data remanence is the possibility that residual representations of information remain after ordinary deletion or attempted removal.
Organisation deletes customer files from an old drive.
Drive is sold.
New owner uses recovery software and retrieves:
previous customer information.
Reuse vs Release vs Destroy
Media remains under organisational control but may move to a different purpose or user.
Media leaves organisational control through return, resale, donation, recycling or other disposition.
Media will no longer be usable as storage media.
Cloud & Logical Media
In cloud environments, organisations may not physically possess the storage media containing their information.
Understand what occurs when a resource or object is deleted.
Copies may exist independently of the original workload.
Provider or customer backups may retain data after primary deletion.
Key management can play an important role in protecting or cryptographically erasing information.
Physical media sanitisation may be performed by the cloud provider.
Agreements should address applicable data-return, deletion and media handling expectations.
☁️ "Delete" in the Cloud Requires Context Logical resources can have multiple underlying copies
Deletes: virtual disk.
Questions may include:
Third-Party Media Handling
Organisations sometimes rely on suppliers for:
Security requirements may therefore include:
Define expected handling and protection.
Restrict access to sensitive material.
Protect media while it is moved.
Specify appropriate sanitisation or destruction.
Obtain appropriate records of disposition where required.
Assess whether supplier practices meet organisational requirements.
📜 Certificate of Destruction Useful evidence - not magical proof by itself
A disposal provider may produce documentation showing which media was processed and how.
The Lost Backup Drive
An employee transports a backup drive between two offices.
The drive is lost on a train.
Drive: unencrypted.
Contains: customer information.
Loss may expose the information directly.
Drive: strongly encrypted.
Key: managed separately.
Physical media is lost, but confidentiality protection is substantially stronger.
Copying Customer Data to USB
Possible Controls
The Encrypted Database
Stolen Laptop
A laptop is stolen from an employee's car.
The Leased Office Copier
A company replaces a multifunction copier after five years.
It is returned to the leasing company.
Security discovers the copier contains internal storage that may hold:
The Forgotten Tape
A data centre closes.
All servers are securely wiped.
Six boxes of old backup tapes remain in:
a storage cupboard.
The Deleted Virtual Machine
Old Employee Laptop
An organisation plans to donate old laptops to charity.
IT performs:
a quick operating-system reinstall.
The devices previously stored:
confidential business information.
Encrypted Cloud Storage
An organisation stores sensitive information encrypted using controlled cryptographic keys.
🎓 CISSP Scenarios Recognise the resource or media-protection principle being tested
A USB drive can be connected to and removed from a computer.
What type of media?
Removable media.
A confidential report is printed on paper.
Does media protection still apply?
Yes.
An organisation assigns identifiers and custodians to backup tapes.
Which activity?
Media management and accountability.
Sensitive media is stored in a locked controlled facility.
Which protection?
Physical media protection.
An encrypted drive is lost during transport.
Which control primarily protects its confidentiality?
Encryption.
Security needs to know which employee currently possesses a sensitive backup device.
Which concept?
Media accountability / tracking.
Does normal media tracking automatically constitute forensic chain of custody?
Answer?
No.
A user plugs an unknown USB device into a production server.
Primary concern?
Uncontrolled removable-media use.
The organisation permits only registered encrypted USB devices.
Which protection technique?
Removable-media / device control.
Security prevents customer records being copied to removable storage.
Which technology may help?
DLP and device control.
A database file sits on an SSD.
Which data state?
Data at rest.
Customer information is being transmitted between an application and database.
Which data state?
Data in transit.
An application has decrypted information into memory for processing.
Which broader data-state concept?
Data in use.
A laptop drive is encrypted but malware running as the logged-in user reads files normally.
Why?
At-rest encryption does not replace endpoint and access controls once authorised decryption is available.
Database storage is encrypted but the network connection is plaintext.
Which gap?
Data-in-transit protection.
Security uses TLS to protect application traffic.
Which data state is primarily being protected?
Data in transit.
Traffic travels only across the internal network.
Does this prove the traffic is encrypted?
No.
TLS terminates at the load balancer and backend traffic is unencrypted.
What should the architect understand?
Where encryption begins and ends.
The organisation encrypts data with a strong algorithm but stores the key beside it with unrestricted access.
Primary weakness?
Key management.
Production data is encrypted but backup exports are plaintext.
Which issue?
The backup copy lacks equivalent protection.
A backup tape contains an entire customer database.
Should it receive weaker controls than production?
No, protection should reflect the sensitivity of the data.
An employee deletes confidential files before selling a drive.
Is ordinary deletion enough?
No.
The organisation reformats a drive containing sensitive data.
Can it automatically assume sanitisation?
No.
Residual information remains recoverable after ordinary deletion.
Which concept?
Data remanence.
Media is logically sanitised so it can be appropriately reused.
Which general sanitisation category may apply?
Clear.
A stronger sanitisation technique is selected because the media will leave organisational control.
Which general category may apply?
Purge.
Media is physically rendered unusable.
Which category?
Destroy.
The organisation sanitises cryptographic key material so encrypted data can no longer be decrypted.
Which technique?
Cryptographic erase.
Cryptographic erase is planned but unencrypted historical copies of the same information exist.
Primary concern?
Not all target data is protected by the erased key.
Sanitisation software reports success.
What should the organisation also consider?
Validation of the sanitisation outcome.
A company returns a leased printer without considering its internal drive.
Which mistake?
Failure to identify embedded storage media.
Confidential documents are left beside a communal printer.
Which issue?
Improper handling of non-digital media.
Sensitive paper documents are placed in ordinary recycling bins.
Which control is missing?
Appropriate media destruction.
A virtual machine is deleted but its snapshots remain.
Has every copy of the data been removed?
No.
In a public cloud, who may physically sanitise failed storage hardware?
Likely answer?
The cloud provider under the shared-responsibility model.
The customer cannot physically access the cloud disk.
Does resource-protection responsibility disappear?
No.
A disposal vendor destroys drives for the organisation.
Has accountability been fully transferred?
No. Third-party governance remains important.
A destruction supplier provides documentation showing which drives were processed.
What does this primarily support?
Accountability and disposition records.
A user can physically steal an unencrypted hard drive but cannot log into the server normally.
Which control could protect the data against offline reading?
Encryption at rest.
An employee can legitimately read a file but should not copy it to an unmanaged USB drive.
Which controls may help?
DLP and removable-media control.
A drive contains public marketing information.
Another contains unreleased acquisition documents.
Should protection necessarily be identical?
No. Protection should reflect classification and risk.
A company transports sensitive media but has no confirmation that the recipient received it.
Which weakness?
Insufficient media-transport accountability.
A sensitive USB drive is encrypted but the decryption password is written on a label attached to it.
Primary weakness?
Credential / key protection defeats the encryption benefit.
An SSD is sanitised using a method designed for a different storage technology without validation.
Primary concern?
The sanitisation method may not be appropriate for the media.
A laptop is internally reassigned from one department to another.
Should previous sensitive data be considered?
Yes. Reuse can require sanitisation too.
A storage device is physically destroyed before resale.
Can it still be reused?
No - destruction renders the media unusable.
An organisation encrypts its laptops but never tests whether recovery keys are securely protected.
Which area needs attention?
Cryptographic key management.
Sensitive cloud storage is deleted from the active service but retained for 30 days in provider backups.
What must be understood?
The complete data-retention and deletion lifecycle.
Management asks what should primarily determine the degree of media protection.
Best answer?
Information sensitivity, risk, media characteristics and applicable requirements.
Management asks for the core principle of 7.5.
Best answer?
Protect information wherever it is stored or moved and ensure it cannot remain accessible when its media is reused or disposed of.
Recognise the Clue Words
USB · Tape · SSD
Stored information.
MediaPortable Storage
Easy to move.
Removable MediaWho Has the Tape?
Tracking.
Media AccountabilityHandling Label
Communicate protection.
Media MarkingLocked Storage Facility
Prevent access.
Media StorageMedia Moves Off-Site
Protect movement.
Media TransportUnknown USB
Malware + data risk.
Media Use ControlBlock USB Copies
Prevent data leaving.
DLP / Device ControlStored on Disk
Static data.
Data at RestAcross Network
Moving data.
Data in TransitBeing Processed
Active data.
Data in UseLost Laptop
Offline confidentiality.
Disk EncryptionWeb / API Traffic
Protected channel.
TLSVPN Traffic
Secure tunnel.
Transit ProtectionStrong Encryption · Exposed Key
Weakness.
Key ManagementDeleted File Recoverable
Residual information.
Data RemanenceReuse Media
Remove old data.
SanitisationLogical Sanitisation
Reuse.
ClearStronger Sanitisation
Higher assurance.
PurgeMedia Unusable
Physical disposition.
DestroyDestroy Encryption Key
Encrypted data inaccessible.
Cryptographic EraseDid Sanitisation Work?
Assurance.
ValidationDelete Cloud VM
Other copies?
Snapshots / BackupsPrinter Returned
Hidden storage.
Embedded MediaDisposal Company
External dependency.
Third-Party Media Handling⚠️ Common CISSP Mistakes Protect the information, not just the device
Media includes disks, tapes, paper, mobile devices, embedded storage and other information-bearing resources.
Printed and other non-digital information still requires protection.
Sensitive digital media may still require access controls and encryption.
Both support accountability but serve different purposes.
Use should reflect business need, risk and policy.
Data classification and authorisation still matter.
Encryption protects confidentiality under certain conditions. Authorisation still determines who should access information.
Physical security, access control, monitoring and key management remain important.
Information may already be decrypted when the system is operating.
Key management is part of cryptographic security.
Protecting stored data does not automatically protect network transmission.
Internal location does not establish cryptographic protection.
Determine exactly where encryption starts and terminates.
Evaluate each copy separately.
Backup media can contain the complete sensitive dataset.
Underlying data may remain recoverable.
The sanitisation technique must provide required assurance for the media involved.
Clear permits media reuse. Destruction renders the media unusable.
Purge represents a stronger sanitisation objective.
Use approved destruction methods suitable for the media.
Storage technologies behave differently.
Appropriate validation strengthens confidence in the result.
Relevant target data must actually depend on the sanitised cryptographic key material.
Snapshots, backups and other copies may remain.
Physical media still exists even when it is controlled by the provider.
Shared responsibility and contractual requirements still apply.
Multifunction devices may contain persistent internal storage.
Supplier governance and appropriate evidence remain important.
Documentation supports the process but does not eliminate supplier oversight.
Data may need to be removed even when the device remains inside the organisation.
An obsolete device may still contain highly valuable information.
Quick Reference
| If you see... | Think... |
|---|---|
| USB, disk, tape, paper | Media |
| Portable storage | Removable Media |
| What media exists? | Media Inventory |
| Who currently possesses it? | Media Accountability |
| Handling designation | Media Marking |
| Locked cabinet / secure room | Media Storage |
| Physical movement | Media Transport |
| Unknown USB | Media Use Risk |
| Control removable storage | Device Control |
| Stop sensitive copying | DLP |
| Stored information | Data at Rest |
| Moving across network | Data in Transit |
| Being processed | Data in Use |
| Protect lost laptop disk | Encryption at Rest |
| Protect web connection | TLS |
| Strong encryption, poor keys | Key Management Problem |
| Old data recoverable | Data Remanence |
| Delete before disposal | Not Sufficient by Itself |
| Remove data for reuse | Sanitisation |
| Logical sanitisation | Clear |
| Stronger sanitisation | Purge |
| Media rendered unusable | Destroy |
| Encrypted data + key sanitised | Cryptographic Erase |
| Was sanitisation effective? | Validation |
| Deleted cloud workload | Check Snapshots + Backups |
| Leased copier returned | Embedded Storage |
| External destruction company | Third-Party Media Handling |
Media Management Memory Aid
Data State Memory Aid
Stored · Moving · Processing
Sanitisation Memory Aid
7.5 Master Memory Aid
Identify → Protect → Track → Sanitise → Validate
The Resource Protection Questions
Key Takeaways
CISSP 7.5 focuses on applying resource protection.
The current CISSP outline explicitly includes media management, media protection techniques and protection of data at rest and in transit.
Media includes physical devices and surfaces on which information is stored or recorded.
It can include hard drives, SSDs, tapes, removable drives, optical media, mobile devices and printed material.
Information-bearing storage may also exist inside devices such as printers, scanners, copiers and network equipment.
Do not protect only obvious storage devices.
Media protection should reflect the sensitivity and value of the information it contains.
A useful operational lifecycle is:
Identify → Classify → Protect → Use → Transport → Sanitise.
Sensitive media should be appropriately inventoried and associated with ownership or custody where required.
Media marking can communicate classification and handling requirements.
Access to sensitive media may require physical, logical and cryptographic controls.
Possession of media should not automatically provide access to its information.
Sensitive media should be appropriately protected during storage.
Physical security, environmental controls, access restrictions and encryption can all contribute to media protection.
Physical media transport creates additional risk because the media leaves its normal controlled location.
Transport controls can include authorisation, encryption, suitable packaging, tracking and confirmation of receipt.
Operational tracking of organisational media and forensic chain of custody are related accountability concepts but should not automatically be treated as identical processes.
Removable media creates particular risks because it is portable and can connect to multiple systems.
Risks include malware introduction, data exfiltration, loss, theft, uncontrolled copying and bypass of normal network controls.
Organisations can restrict removable-media use through device controls, approved-media policies, encryption, DLP, malware scanning and logging.
Removable media should be allowed according to need and risk - not simply because a USB port exists.
Media protection techniques can include encryption, access control, physical protection, device control, DLP, integrity protection, write protection, malware scanning, backup and sanitisation.
Protection should follow the information's classification.
Data at rest refers to stored information.
Examples include databases, files, backups, disks and cloud object storage.
Data in transit refers to information being transmitted between systems or services.
Examples include web traffic, API calls, database connections and remote communications.
Data in use describes information actively being processed.
Rest = stored. Transit = moving. Use = processing.
Data at rest can be protected through encryption, access control, physical security, monitoring and appropriate key management.
Full-disk encryption is particularly valuable against offline access to a lost or stolen storage device.
Full-disk encryption does not replace access controls or endpoint security once an authorised system has unlocked the storage.
Cryptographic protection depends on appropriate key management.
A strong encryption algorithm provides little confidentiality if an attacker can easily obtain the required key.
Encrypt the data. Protect the key.
Data in transit can be protected using secure communication mechanisms such as TLS, IPsec, VPN technologies and SSH depending on the use case.
Transport protection can provide confidentiality, integrity and endpoint authentication.
Encryption at rest and encryption in transit protect different data states.
Encrypted disk ≠ encrypted network connection.
Similarly, use of a private or internal network does not automatically mean communications are encrypted.
When evaluating encrypted communications, determine where encryption begins and where it terminates.
TLS may terminate at a reverse proxy or load balancer while subsequent traffic takes a different protected or unprotected path.
Backups require the same security thinking as other copies of sensitive information.
Production encryption does not automatically guarantee that backup exports, snapshots or archives are encrypted.
Another copy of the data = another asset to protect.
Printed information remains media and should be protected according to its sensitivity.
Sensitive documents should not be left unattended at shared printers or disposed of through inappropriate ordinary waste processes.
Devices such as multifunction printers may themselves contain persistent storage.
Embedded storage should therefore be included in equipment retirement and sanitisation processes.
Media sanitisation becomes important before media is reused, reassigned, returned, recycled, sold, donated or otherwise released.
Ordinary file deletion should not automatically be considered secure sanitisation.
Reformatting a device also does not automatically provide appropriate sanitisation assurance.
Looks empty ≠ data unrecoverable.
Data remanence describes residual data remaining after ordinary deletion or attempted removal.
Sanitisation methods should be selected according to information sensitivity, storage technology and the media's intended disposition.
Clear, Purge and Destroy are important sanitisation concepts.
Clear uses suitable logical sanitisation techniques.
Purge provides stronger sanitisation assurance.
Destroy renders the media unusable.
Clear = logical sanitisation. Purge = stronger sanitisation. Destroy = media unusable.
Sanitisation techniques are media-specific.
A technique appropriate for magnetic media may not be appropriate for flash storage, optical media or cloud storage.
Cryptographic erase can render encrypted data inaccessible by appropriately sanitising the cryptographic key material required to recover it.
Its effectiveness depends on suitable encryption and complete management of relevant key material and data copies.
Crypto erase works because the ciphertext becomes inaccessible without the required key.
Modern sanitisation programmes should include appropriate validation of sanitisation effectiveness.
Running a sanitisation process successfully does not by itself provide the strongest possible assurance that the desired outcome was achieved.
Sanitise → Validate → Record.
Media can be sanitised for internal reuse as well as before it leaves the organisation.
A device being passed to another employee may still contain information the new user should not receive.
Cloud computing changes how media protection is implemented because the customer frequently does not control the underlying physical storage.
Cloud data may exist in active resources, snapshots, backups and other provider-managed copies.
Deleting a virtual machine or cloud object does not necessarily mean that every copy immediately disappears.
Provider deletion mechanisms, retention behaviour, encryption, cryptographic keys and contractual requirements therefore become important.
Cloud changes who controls the physical media. It does not eliminate media-protection responsibility.
Third parties may also transport, store, sanitise or destroy media.
Supplier contracts, due diligence, handling requirements and disposition evidence can support appropriate control.
Outsourcing media destruction does not eliminate the organisation's need to govern the risk.
Certificates or records of destruction can provide useful evidence of disposition but should not replace appropriate supplier assurance.
The central CISSP principle is:
identify where sensitive information exists, protect it according to its classification while stored and transmitted, control the media that carries it and ensure residual information cannot remain accessible when that media is reused or leaves organisational control.
📚 Sources & Further Reading Current and foundational media-protection references
- ISC2 - CISSP Certification Exam Outline
View the current CISSP Exam Outline - NIST SP 800-88 Rev. 2 - Guidelines for Media Sanitization
View current NIST media-sanitisation guidance - NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations
View NIST SP 800-53 - NIST SP 800-171 Rev. 3 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
View NIST SP 800-171 Rev. 3 - NIST SP 800-111 - Guide to Storage Encryption Technologies for End User Devices
View NIST storage-encryption guidance - NIST - Removable Media Glossary
View NIST removable-media terminology - NIST - Data at Rest Glossary
View NIST data-at-rest terminology - NIST - Data in Transit Glossary
View NIST data-in-transit terminology
