Policy
Specified Information moves between systems through the enclave file server or the approved transfer tool. Removable media is used only when no other path exists, only on inventoried, hardware-encrypted drives issued by [role], and is logged out and back in. Laptops and portable drives holding Specified Information use full-disk encryption with the key escrowed by [role]. Printed Specified Information is collected from the printer immediately and shredded when no longer needed.
Media leaving [Company]'s control, whether for disposal, reuse, warranty return, or repair, is sanitized first, to a method recognized in ITSP.40.006 or NIST SP 800-88: cryptographic erase followed by physical destruction for solid-state media, degaussing or shredding for magnetic media. Drilling holes is not a sanitization method. Warranty replacements for failed drives are requested with media retention so the failed drive stays on site. Every sanitization or destruction is logged with evidence.
Sanitization and destruction log
Date Asset / serial Media type Data class Method Verified by Evidence
[date] [asset] / [serial] [HDD/SSD/USB] SI [crypto erase / degauss / shred / vendor] [name] [photo, cert #, tool log]