EUS_Attachment_Seven_(7)_-_USPTO_Media_Protection_Procedures.pdf

PDF 1 MB Posted

Attached to
Information Technology End User Support Services Federal contract opportunity
Solicitation number
DOC52PAPT1500005
Issued by
Department of Commerce US Patent and Trademark Office

About this file

Attachment 7 USPTO Media Protection Procedures

View the file

Other files for this federal contract opportunity

Other files attached to Information Technology End User Support Services, newest first.
File Type Posted
Amendment_7_Posting.pdf PDF
Amendment_6_Posting.pdf PDF
Additional_Questions_9_15_2015.pdf PDF
Additional_Questions_from_posting_of_Amendment_0005.pdf PDF
Amendment_5_Posting.pdf PDF
EUS_Attachment_Four_(4)_-_Warehouse_Operations_Historical_Data.pdf PDF
ATTACHMENT_A_EUS_Consolidated_Questions_DLF_04SEPT2015_MASTER_FINAL.pdf PDF
Amendment_0004.pdf PDF
EUS_Attachment_Six_(6)_-_List_of_Acronyms.pdf PDF
J.4_Copy_of_Templates_Informational_Purposes_Only.xls XLS spreadsheet
EUS_Attachment_Five_(5)_-_Technical_Writer_Document_Development_Historical_Data.pdf PDF
EUS_Attachment_Eleven_(11)_-_CSB_Change_Management-Procedure.pdf PDF
ATTACHMENT_B_EUS_DOC52PAPT1500005__DLF_04SEPT2015_MASTER_FINAL.pdf PDF
EUS_Attachment_Eight_(8)_Nine_(09)_ _Ten_(10)_-_Electronic_Business_Center_-_Supported_System_Description.pdf PDF
EUS_Attachment_One_(1)_-_Labor_Category_Descriptions_and_Rates_(Modified).xls XLS spreadsheet
EUS_Attachment_Two_(2)_-_Past_Performance_Questionnaire.pdf PDF
EUS_Attachment_Three_(3)_-_DFS_Historical_Data.pdf PDF
Amendment_0003.pdf PDF
DOC52PAPT1500005_Amendment_0001.pdf PDF
DOC52PAPT1500005_END_USER_SUPPORT_SERVICES_SOLICITATION.pdf PDF
EUS_Attachment_Three_(3)_-_DFS_Historical_Data.pdf PDF
EUS_Attachment_Five_(5)_-_Technical_Writer_Document_Development_Historical_Data.pdf PDF
EUS_Attachment_Seven_(7)_-_USPTO_Media_Protection_Procedures.pdf PDF
EUS_Attachments_Eight_(8)_Nine_(9)__Ten_(10)_-_Electronic_Business_Center_-_Supported_System_Description.pdf PDF
EUS_Attachment_Two_(2)_-_Past_Performance_Questionnaire.pdf PDF
EUS_Attachment_One_(1)_-_Labor_Category_Descriptions_and_Rates.xls XLS spreadsheet
EUS_Attachment_Five_(5)_-_Technical_Writer_Document_Development_Historical_Data.pdf PDF
EUS_Attachment_Six_(6)_-_List_of_Acronyms.pdf PDF
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

UNITED STATES

PATENT AND TRADEMARK OFFICE (USPTO)

MEDIA PROTECTION PROCEDURES

December 16, 2013

Version: 1.1

For Official Use Only

Media Protection Procedures

1112/2012 2/3/2012 5/912012 12/16/2013

Document History

First Release Initial Revision Updated to address NIST 800 53 rev 4 re uirements ii

December 2013

Media Protection Procedures December 2013

Table of Contents

1 INTRODUCTION

1.1 BACKGROUND

1.2 PURPOSE

1.3 SCOPE, MANAGEMENT COMMITMENT, APPLICABILITY

1.4 UPDATE AND REVIEW

1.5 AUTHORITY ..................................................................................................................................................... l

1.6 COMPLIANCE

2 SECURITY CONTROL SCOPING GUIDANCE

3 SECURITY PROCEDURES FOR NIST FAMILY OF CONTROLS (MP)

3.1 MEDIA PROTECTION

3.2 MEDIA PROTECTION POLICY AND PROCEDURES (MP-!)

3.3 MEDIA ACCESS (MP-2)

3.4 MEDIA LABELING (MP-3)

3.5 MEDIA STORAGE (MP-4)

3.6 MEDIA TRANSPORT(MP-5)

3.7 MEDIA SANITATION (MP-6)

3.8 MEDIA USE (MP-7)

APPENDIX A: SANITIZATION METHODS

APPENDIX B: MEDIA SANITIZATION DECISION MAKING

4 MEDIA PROTECTION PROCEDURES APPROVAL ................................................................................ I lll

Media Protection Procedures

1 Introduction

1.1 Background

December 2013

Based on federal requirements and mandates, the United States Patent and Trademark Office (USPTO) is responsible for ensuring that all USPTO information systems meet the minimum security requirements defined in the Federal Information Processing Standards (FIPS) Publication (PUB) 200, Minimum Security Requirements for Federal Information and Information Systems. All USPTO information systems must meet the security requirements through the use of the security controls in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Revision 4, Security and Privacy Controls for Federal Information systems and Organizations.

USPTO has developed Media Protection procedures to ensure the integrity, confidentiality, and availability of its information and information systems. These procedures are consistent with applicable federal laws, Executive Orders, directives, regu.lations, standards, and guidance. These procedures I standards are set forth by USPTO and, in compliance with, the Media Protection family of controls found in NIST SP 800-53, Revision 4, the USPTO IT Security Handbook, and the Department of Commerce Information Technology Security Program Policy (ITSPP). The procedures enumerated within this document are mandatory for USPTO information systems in accordance with each system's respective security baseline level.

1.2 Purpose

The purpose of these procedures is to provide guidance on implementing the USPTO IT Security Handbook for Media Protection. The Media Protection procedures address all areas identified in the IT Security Handbook and address implementations of all associated Media Protection controls.

1.3 Scope, Management Commitment, Applicability

The provisions of these procedures pertain to all US PTO information systems and organizational entities at USPTO. USPTO senior management shall ensure that each information system operated by or on behalf of US PTO receive adequate security equivalent to the safeguards required of systems operated internally to the Federal Government. Systems under development must meet the security planning requirements commensurate with the sensitivity of the information they house and the current life cycle phase.

1.4 Update and Review

USPTO disseminates, reviews, and/or updates security procedures at least annually when review indicates updates are required.

1.5 Authority

These procedures are issued under the authority of the USPTO Chief Information Officer (CIO). The most critical Federal laws, regulations, Executive Orders, policies, standards, and directives pertaining to Media Protection are indicated below.

• E-Govemment Act of2002

• The Privacy Act ofl 97 4

• Clinger-Cohen Act of 1996

• National Technology Transfer and Advancement Act of 1996

• Federal Information Security Management Act of2002 (FISMA)

• Federal Financial Management Improvement Act of 1996 (FFMIA)

• Federal Acquisition Streamlining Act of 1994 (F ASA)

• United States Government Accountabili1y Office, Federal Information System Controls Audit

Manual (FISCAM)

• OMB Circulars

• OMB Memoranda

• Federal Information Processing Standards (FIPS)

• NIST Special Publications

• Department of Commerce ITSPP

I. 6 Compliance Compliance with these procedures is mandatory. It is USPTO policy that personnel and information systems abide by or exceed the requirements outlined in this procedure and the USPTO IT Securi1y Handbook. The Senior Information Securi1y Officer (SISO) will periodically assess USPTO's adherence with these procedures through various oversight and compliance measures.

All USPTO information systems will apply the Media Protection procedures consistently; any anomalies or problems with applying the procedures will need to be documented. In cases where an infonnation system cannot comply with these procedure for technical or financial reasons, or because it precludes USPTO from supporting mission or business functions, justifications for non-compliance must be documented using the USPTO Risk Acceptance Memo process, addressed by the System Owner (SO), and submitted to the CIO via the SISO.

2 Security Control Scoping Guidance The following table displays recommended securi1y control baselines for low-impact, moderate-impact, and high-impact information systems per NIST SP 800-53 Rev. 4. Priori1y codes associated with each control in the baselines are intended to assist in making sequencing decisions for securi1y control implementation.

• •• i'v1fi'5 (4). • tv1F>-6 (1) (2) (3)\

•••tvi~'T t1)".i•·:

• Nbis)j1ed~a • Nots~f~C"i;,"~.

3 Security Procedures for NIST Family of Controls (MP)

3.1 Media Protection

The media protection program consists of the process oflabeling, storing, accessing, transporting, sanitizing, and destroying media for an infonnation system for the purpose of safeguarding information.

Media are defined as any object, device, printed ontput, or otber hardware on which information system data is stored. Refer to Appendix B.' Media Sanitization Decision Making for a list of different media types and how to sanitize snch media. Media protection is necessary to protect information resources from harm or misuse. The process begins by evaluating the security needs of the system and the protections required for the mission and information held. The resulting characterization is tben used to determine the appropriate minimum security control baseline and system specific security controls required for protecting the information resources. The controls are documented in a System Security Plan (SSP) and implemented by the SO. Used in conjunction with the security categorization of the information system, the figure below has been provided and must be used in determining how to sanitize or dispose of media that is or was part of an information system.

Sanitization and Disposition Decision Flow

3.2. Media Protection Policy and Procedures (MP-1)

The USPTO IT Security Handbook is the official source for USPTO-specific policy on the Media Protection control family. Media Protection Policy included in the USPTO IT Security Handbook is reviewed and updated as necessary, or at least on an annual basis by the USPTO key stakeholders. MP control family procedures are enumerated in this document (Media Protection Procedures), which is also reviewed and updated as necessary on an annual basis.

3.3 Media Access (MP-2)

USPTO restricts access to sensitive media, including but not limited to, diskettes, magnetic tapes, external/removable hard drives, flash/thumb drives, compact disks, digital video disks and non-digital media including but not limited to paper and microfilm, to authorized individuals using physically secure locations. Media storage for the USPTO information systems is housed in the Data Center, at the Madison West Building (MDW) on the 3'd floor. Authorized personnel must use their USPTO badge and enter a PIN in order to enter the Data Center. Visitors to the Data Center must sign in with the guards stationed outside of the center and must be accompanied at all times by an authorized escort with valid access authorization to the Data Center. In addition, USPTO stores commercial off the shelf(COTS) software in the Configuration Management (CM) library housed in the MDW on the 5tli floor, which is secured with a proximity card reader.

Note that this control is applicable to media storage areas within the agency where a significant volume of media is stored (e.g. Storage Area Network (SAN)) but is not applicable to every location where some media is stored (e.g. in individual offices or access controlled by guard station).

3.4 Media Labeling (MP-3)

External marks must be affixed to removable information storage media and infonnation system output.

USPTO information systems must mark, in accordance with agency policies and procedures, removable information system media and information system output indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information. Information system personnel shall affix printed output with cover sheets (developed by the applicable information system perso1mel) ifthe printed output is not otherwise appropriately marked. Digital media and cover sheets should be labeled with the following:

• Distribution limitations

• Handling caveats of the information

• Applicable security markings (e.g., For Official Use Only, Sensitive But Unclassified), if applicable.

US PTO does not exempt specific types of media or hardware components from marking even if they remain within a secure environment. A secure enviromnent is defined as a locked room either accessible by manual key, key fob, Personal Identify Verification (PIV) card, or cipher lock.

3.5 Media Storage (MP-4)

USPTO physically controls and securely stores information system media, both paper and digital, based on the highest FIPS 199 security category of the information recorded on the media. All US PTO infonnation processed or stored is designated as Sensitive But Unclassified (SBU), and is required to be handled and stored in a manner appropriate to this classification unless otherwise designated. Information system personnel should physically control and securely store sensitive digital media including, but not limited to, diskettes, magnetic tapes, external/removable hard drives, flash/thumb drives, compact disks, digital video disks and non-digital media including, but not limited to, paper and microfilm. This media will be restricted to only authorized personnel, within approved USPTO secure locations, based on approved access control lists.

USPTO secure location would include an area or space for which USPTO has confidence that the physical procedures are sufficient to meet the requirements established for protecting the information system media (i.e., a locked room either accessible by manual key, key fob, Personal Identify Verification (PIV) card, or cipher lock linked to the HSPD-12 system). USPTO storage and processing media along· with the backup media is housed in the USPTO Data Center. Access to the USPTO Data Center is restricted only to authorized personnel who must use their USPTO badge and enter a PIN in order to access the Data Center. Any visitor to the Data Center must sign in with the guards stationed outside of the center and must be accompanied at all times by an authorized escort with valid access authorization.

COTS is required to be stored in the CM Library which is secured with a card reader.

Information system personnel should protect information system media until the media are destroyed or sanitized using approved equipment, techniques, and procedures. Any unmarked media must be protected at the highest FIPS 199 security category for the information system until the media are reviewed and appropriately labeled, at which time the commensurate measure will be employed.

3.6 Media Transport (MP-5)

USPTO protects and controls information system digital and non-digital media during transport outside of controlled areas using hand delivery and restricts the activities associated with transport of such media to authorized personnel. Digital media may include, for example, diskettes, magnetic tapes, external/removable hard disk drives, flash drives, compact disks, and digital video disks. Non-digital media includes, for example, paper and microfilm. Only authorized personnel can transport or receive USPTO media. When media is stored at an offsite storage facility, it must be properly transported within fire rated metal containers, be stored in storage racks with fire suppression systems and temperature/humidity monitoring controls in place; and must have a completed property pass logged by the Data Center guards.

All backup tapes, when in transit or stored at alternate storage facilities, should be encrypted to protect the confidentiality and integrity ofUSPTO information. Sensitive information in hardcopy or removable media must not be removed from the USPTO premises without prior authorization.

Also, cryptographic mechanism should be implemented to protect confidentiality and integrity of information stored on digital media including portable storage devices such as USB memory stick, digital video disks, external/removable hard disk drives and mobile devices with storage capability such as smart phones, tablets etc. during transport outside of controlled areas.

Procedures shall be followed for handling extracted data containing sensitive PII which is physically transported outside of the US PTO premises.

In order to remove data extracts containing sensitive PII from USPTO premises, users must:

• Maintain a centralized office log for extracted datasets that contain sensitive PI!. This log must include the date the data was extracted and removed from the facilities, a description of the data extracted, the purpose of the extract, the expected date of disposal or return, and the actual date of return or deletion.

• Ensure that any extract which is no longer needed is returned to USPTO premises or securely erased, and that this activity is recorded on the log.

• Obtain management concurrence in the log, if an extract aged over ninety (90) days is still required. ·

• Store all PII data extracts maintained on an USPTO laptop in the encrypted My Documents directory. This includes any sensitive PII data extracts downloaded via the USPTO Virtual Private Network.

• Encrypt and password-protect all sensitive PII data extracts maintained on a portable storage device (such as CD, memory key, flash drive, etc.). Exceptions due to technical limitations must have an adequate approval and alternative protective measures must be in place prior to removal from USPTO premises.

• Encrypt and password-protect prior to transmission any sensitive PII data extracts that are sent to an external e-mail address via the Internet. The password key should be forwarded to the recipient in a separate e-mail from the attached file.

The automatic on-line remote back-up of network servers is excluded from the extract logging requirement.

3. 7 Media Sanitation (MP-6)

Sanitization refers to a process that renders access to target data on the media infeasible for a given level of effort. Sanitizations techniques, including clearing, purging, and destruction prevent the disclosure of information to unauthorized individuals when such media is reused or released for disposal.

Sanitization also includes removing all labels, markings, and activity logs.·

USPTO must sanitize information system media, both digital and non-digital, using approved equipment, techniques, and procedures prior to disposal, and/or release out of department control, or release for reuse.

The USPTO should track, document, and verify media sanitization and destruction actions and periodically test sanitization equipment and procedures to ensure correct performance. All components marked for salvage, surplus, or disposal must be retrieved and sent to the Evo!ver Inc contract staff. This group will determine what components are destroyed and how, including internal hard drives, tapes, and diskettes. All other equipment will be reviewed to determine if it can be sanitized with software that meets DOD Standard 5220.00 Mor running them through a degausser machine and then physically damaging the media source. The degausser must have a degaussing force of 4000 gauss and erasure depth of between 75 and 90 db. Proper sanitization must be confirmed by analysis of the media following sanitization procedures.

For media that is sanitized for re-deployment or re-use, the following steps must be followed:

• Desktop/Server - Nothing happens when returned from a user and the unit is in a holding area waiting to be deployed. When they are deployed, a new approved baseline is added to the unit which writes over any old information on the machine prior to deployment to a new user.

• Laptops - When the laptop is returned it is checked to make sure it is still operational then it is disk wiped by the program Active@Ki!!Disk Pro for Windows and the triple wipe per DOD standard 5220.00 Mis selected to be run. Once completed the unit is then stored until deployed and the approved baseline and safeboot programs are added.

For media that are deemed snrplus, the following steps must be followed:

• Desktop/Server - Designated Evolver Inc. personnel runs the program Active@KillDisk Pro for Windows on the hard drive. They select the triple wipe per approved DOD standards and if it passes then the system is processed on through the surplus process. If the triple wipe fails they pull the hard drive from the unit and run the hard drive through a HD-I professional Degausser.

The CPU shell is then processed through surplus and the hard drive is disposed of accordingly.

• Laptops - Designated Evolver Inc. personnel runs Active@KillDisk Pro program for Windows and then removes the hard drive from the unit and then runs the hard drive through the HD- I professional Degausser. The laptop shell is then processed through surplus and the hard drive is disposed accordingly.

All media sanitization equipment, techniques, and procedures must comply with NIST SP 800-88.

USPTO must also sanitize portable, removable storage devices prior to connecting such devices to the information system. This needs to be especially implemented in the case of any equipment returning from an international travel. If the equipment has been taken internationally, it must be properly sanitized prior to connecting to any USPTO information system or network. Sanitization procedures for these devices and all other USPTO equipment must follow the sanitization methods in Appendix A and the media sanitization decision making process in Appendix B. For additional details please refer to the USPTO !reformation Security Foreign Travel Policy (OCIO-POL-6).

3.8 Media Use (MP-7)

USPTO restricts the use of flash drives or external hard drives on all workstations and mobile devices using nontechnical safeguards including US PTO Rules of the Road and associated policy and procedures that must be followed by all USPTO employees. Only organization approved portable storage devices should he used. USPTO prohibits the use of portable storage devices in organizational information systems when such devices have no identifiable owner.

Media Protection Procedures December2013

Clear

Purge

Appendix A: Sanitization Methods

One method to sanitize media is to use software or hardware products to overwrite user-addressable storage space on the media with non-sensitive data, using the standard read and write commands for the device. This process may include overwriting not only the logical storage location of a file(s) (e.g., file allocation table) but also should include all user-addressable locations. The security goal of the overwriting process is to replace Target Data with non-sensitive data. Overwriting cannot be used for media that are damaged or not rewriteable, and may not address all areas of the device where sensitive data may be retained. The media type and size may also influence whether overwriting is a suitable sanitization method. For example, flash-based storage devices may contain spare cells and perform wear leveling, making it infeasible for a user to sanitize all previous data using this approach because the device may not support directly addressing all areas where sensitive data has been stored using the native read and write interface.

The Clear operation may vary contextually for media other than dedicated storage devices, where the device (such as a basic cell phone or a piece of office equipment) only provides the ability to return the device to factory state (typically by simply deleting the file pointers) and does not directly support the ability to rewrite or apply media-specific techniques to the non-volatile storage contents. Where rewriting is not supported, manufacturer resets and procedures that do not include rewriting might be the only option to Clear the device and associated media. These still meet the defmition for Clear as long as the device interface available to the user does not facilitate retrieval of the Cleared data.

Some methods of purging (which vary by media and must be applied with considerations described further throughout this document) include overwriting, block erase, Cryptographic Erase, through the use of dedicated, standardized device sanitize commands that apply media-specific techniques to bypass the abstraction inherent in typical read and write commands. One type of data that could remain without invalidating the sanitization procedure is device log data, which is not necessarily sanitized when using the available interface commands.

Destructive techniques also render the device Purged when effectively applied to the appropriate media type, including incineration, shredding, disintegrating, degaussing, and pulverizing. The common benefit across all these approaches is assurance that the data is infeasible to recover using state of the art laboratory techniques. However, Bending, Cutting, and the use of some emergency procedures (such as using a firearm to shoot a hole through a storage device) may only be Damage techniques if the action does not cover the whole surface of the media, as portions of the media may remain undamaged and therefore accessible using advanced laboratory techniques:

Degaussing renders a Legacy Magnetic Device Purged when the strength of the degausser is carefully matched to the media coercivity. Coercivity may be difficult to determine based only on information provided on the label. Therefore, refer to the device manufacturer for coercivity details. Degaussing should never be solely relied upon for flash-based storage devices or for magnetic

1 NIST SP 800-88 Revision 1, Guidelines.for Media Sanitization

A-1

Media Protection Procedures December2013

There are many different types, techniques, and procedures for media Destruction. While some techniques may render the Target Data infeasible to retrieve through the device interface and unable to be used for subsequent storage of data, the device is not considered Destructed unless Target Data retrieval is infeasible using state of the art laboratory techniques.

• Disintegrate, Pulverize, Melt, and Incinerate. These sanitization methods are designed to completely Destruct the media. They are typically carried out at an outsourced metal Destruction or licensed incineration facility with the specific capabilities to perform these activities effectively, securely, and safely.

• Shred. Paper shredders can be used to Destruct flexible media such as diskettes once the media Destroy are physically removed from their outer containers. The shred size of the refuse should be small enough that there is reasonable assurance in proportion to the data confidentiality that the data carmot be reconstructed. To make reconstructing the data even more difficult, the shredded material can be mixed with non-sensitive material of the same type (ie. shredded paper).

The application of Destructive techniques may be the only option when the media fails and other Clear or Purge techniques cannot be effectively applied to the media, or when the validation ofClear or Purge methods fails (for known or unknown reasons).

A-2

Appendix B: Media2 Sanitization Decision Making Hard Copy Storage

NI A, see Destruct.

Destruct paper using cross cut shredders which produce particles that are I x 5 millimeters in size (or smaller), or pulverize/disintegrate paper materials using disintegrator devices equipped with 3/32 inch security screen. Destruct microforms (microfilm, microfiche, or other reduced ima e hoto ne atives b burnin .

When material is burned, residue must be reduced to white ash.

Perform a full manufacturer's reset to reset the router or switch back to its factory default settin s.

See Destruct. Most routers and switches only offer capabilities to Clear (and not Purge) the data contents. A router or switch may offer Purge capabilities, but these capabilities are specific to the hardware and firmware of the device and should be applied with caution.

Refer to the device manufacturer to identify whether the device has a Purge capability that applies media-dependent techniques (such as rewriting or block erasing) to ensure that data recove is infeasible, and that the device does not sim ly remove the file ointers.

Shred, Disintegrate, Pulverize, or Incinerate by burning the device in a licensed incinerator.

For both Clear and (if applicable) Purge, refer to the manufacturer for additional information on the proper Sanitization procedure. Network Devices may contain removable storage. The removable media ·must be removed and sanitized using media s ecific techni ues.

Shred, Disintegrate, Pulverize, or Incinerate by burning the device in a licensed incinerator.

Following the Clear/Purge operation, manually navigate to multiple areas of the device (such as browser history, files, photos, etc.) to verify that no personal information has been retained on the device.

Refer to the manufacturer for proper sanitization procedure, and for details about implementation differences between device versions and OS versions. Proper initial configuration using guides such as the DISA ST!Gs (http://iase.disa.mil/stigs/) helps ensure that the level of data rotection and sanitization assurance is as robust as ossible.

Select the full sanitize option (typically in either the 'Options> Security Options> General Settings> [menu button]> Wipe Handheld' OR in 'Options> Security Options>

2 NIST SP 800-88 Revision 1, Guidelines for Media Sanitization

B-1

Security Wipe' menu), making sure to select all subcategories of data types for sanitization. The sanitization operation may take as long as several hours depending on the media size.

Shred, Disintegrate, Pulverize, .or Incinerate by burning the device in a licensed incinerator.

Following _the Clear/Purge operation, manually navigate to multiple areas of the device (such as browser history, files, photos, etc.) to verify that no personal information has been retained on the device.

Refer to the manufacturer for additional information on the proper sanitization procedure, and for details about implementation differences between device versions and OS versions. Proper initial configuration using guides such as the DISA ST!Gs (http://iase.disa.mil/stigs/) helps ensure that the level of data protection and sanitization assurance is as robust as possible. If the device contains removable storage media, ensure that the media is sanitized using appropriate media-dependent procedures.

Select the full sanitize option (typically in the 'Menu> Settings> [Privacy OR SD and Phone Stora e ]> Facto data reset' menu .

Android settings and capabilities may be modified by device vendors or service providers, and therefore no assumptions should be made about the level of assurance provided by performing a factory data reset. Some versions of Android support encryption, and may support Cryptographic Erase. Refer to the device manufacturer (and potentially the service provider as well, if applicable) to identify whether the device has a Purge capability that applies media-dependent techniques (such as rewriting or block erasing) or Cryptographic Erase to ensure that data recovery is infeasible, and that the device does not simply remove the file ointers.

Shred, Disintegrate, Pulverize, or Incinerate by burning the device in a licensed incinerator.

Proper initial configuration using guides such as the DISA STIGs (http://iase.disa.mil/stigs/) helps ensure that the level of data protection and sanitization assurance is as robust as possible.

Following the Clear or (if applicable) Purge operation, manually navigate to multiple areas of the device (such as browser history, files, photos, etc.) to verify that no personal information has been retained on the device. For both Clear and (if applicable) Purge, refer to the manufacturer for additional information on the ro er sanitization rocedure.

Manually delete all information, then perform a full manufacturer's reset to reset the mobile device to facto state.

See Destruct. Many mobile devices only offer capabilities to Clear (and not Purge) the data contents. A mobile device may offer Purge capabilities, but these capabilities are specific to the hardware and software of the device and should be applied with caution.

The device manufacturer should be referred to in order to identify whether the device has a Purge capability that applies media-dependent techniques (such as rewriting or block erasing) or Cryptographic Erase to ensure that data recovery is infeasible, and that the device does not sim l remove the file ointers.

Shred, Disintegrate, Pulverize, or Incinerate by burning the device in a licensed incinerator.

Following the Clear or (if applicable) Purge operation, manually navigate to multiple areas of the device (such as call history, browser history, files, photos, etc.) to verify that no personal information has been retained on the device.

For both Clear and (if a licable) Purge, refer to the manufacturer for ro er sanitization

B-2

Perform a full manufacturer's reset to reset the office equipment to its factory default settin s.

See Destruct. Most office equipment only offers capabilities to Clear (and not Purge) the data contents. Office equipment may offer Purge capabilities, but these capabilities are specific to the hardware and firmware of the device and should be applied with caution.

Refer to the device manufacturer to identify whether the device has a Purge capability that applies media-dependent techniques (such as rewriting or block erasing) or Cryptographic Erase to ensure that data recovery is infeasible, and that the device does not simply remove the file pointers. Office equipment may have removable storage media, and if so, media-de endent sanitization techni ues ma be a lied to the associated stora e device.

Shred, Disintegrate, Pulverize, or Incinerate by burning the device in a licensed incinerator.

For both Clear and (if applicable) Purge, manually navigate to multiple areas of the device (such as stored fax numbers, network configuration information, etc.) to verify that no personal infonnation has been retained on the device.

For both Clearing and (if applicable) Purge, the ink, toner, and associated supplies (drum, fuser, etc.) should be removed and destroyed or disposed of in accordance with applicable law, environmental, and health considerations. Some of these supplies may retain impressions of data printed by the machine and therefore could pose a risk of data exposure, and should be handled accordingly. If the device is functional, one way to reduce the associated risk is to print a blank page, then an all-black page, then another blank page. For devices with dedicated color components (such as cyan, magenta, and yellow toners and related supplies), one page of each color should also be printed between blank pages. The resulting sheets should be handled at the confidentiality of the Office Equipment (prior to sanitization). Note that these procedures do not apply to supplies such as ink/toner on a one-time use roll, as they are typically not used again and therefore will not be addressed by sending additional pages through the equipment. Office Equipment supplies may also pose health risks, and should be handled using appropriate procedures to minimize exposure to the print components and toner.

For both Clear and (if applicable) Purge, refer to the manufacturer for additional information on the ro er sanitization rocedure.

B-3 using a system with similar characteristics to the one that originally recorded the data. For example, overwrite previously recorded sensitive VHS format video signals on a comparable VHS format recorder. All portions of the magnetic tape should be overwritten one time with known non-sensitive signals. Clearing a magnetic tape by re-recording (overwriting) may be impractical for most applications since the process occupies the tape trans ort for excessive time eriods.

Overwrite media by using organizationally approved and validated overwriting technologies/methods/tools. The Clear pattern should be at least a single pass with a fixed data value, such as all zeros. Multiple passes or more complex values may alternatively be used.

Four options are available:

1. Apply the A TA sanitize command, if supported. One or both of the following options may be available:

• The overwrite command. Apply one pass of a fixed pattern across the media surface. Some examples of fixed patterns include all Os or a pseudorandom pattern. Optionally: Instead of one pass, use three total passes of a pseudorandom pattern, leveraging the invert option so that the second pass is the inverted version of the pattern specified.

• If the device supports encryption and the requirements described in this document have been satisfied, the Cryptographic Erase (also known as sanitize crypto scramble) command. Optionally: After Cryptographic Erase is successfully applied to a device, use the overwrite command (if supported) to write one pass of zeros or a pseudorandom pattern across the media. If the overwrite command is not supported, the Secure Erase or the Clear procedure could alternatively be applied following Cryptographic Erase.

2. Apply the ATA Secure Erase command. The ATA sanitize command is preferred to AT A Secure Erase when the AT A sanitize command is supported by the device.

3. Cryptographic Erase through the Trusted Computing Group (TCG) Opal Security Subsystem Class (SSC) or Enterprise SSC interface by issuing commands as necessary to cause all MEKs to be changed (if the requirements described in this document have been satisfied). Refer to the TCG and device manufacturers for more information. Optionally: After Cryptographic Erase is successfully applied to a device, use the overwrite command (if supported) to write one pass of zeros or a pseudorandom pattern across the media. If the overwrite command is not supported, the Secure Erase or the Clear procedure could alternatively be applied following Cryptographic Erase. ·

I. Degauss in an organizationally approved automatic degausser or disassemble the hard disk drive and Purge

Shred, Disintegrate, Pulverize, or Incinerate by burning the device in a licensed incinerator.

Verification must be performed for each technique within Clear and Purge, except degaussing. The assurance provided by degaussing depends on selecting an effective degausser, applying it appropriately and periodically spot checking the results to ensure it is workin as ex ected.

B-4

When using the three pass ATA sanitize overwrite procedure with the invert option, the verification process would simply search for the original pattern (which would have been written again during the third pass).

The storage device may support configuration capabilities that artificially restrict the ability to access portions of the media as defined in the A TA standard, such as a Host Protected Area (HPA), Device Configuration Overlay (DCO), or Accessible Max Address.

Even when a dedicated sanitization command addresses these areas, their presence may affect the ability to reliably verify the effectiveness of the sanitization procedure ifleft in place. Any configuration options limiting the ability to access the entire addressable area of the storage media should be reset prior to applying the sanitization technique. Recovery data, such as an OEM-provided restoration image may have been stored in this manner, and sanitization may therefore impact the ability to recover the system unless reinstallation media is also available.

When Cryptographic Erase is applied, verification must be performed prior to additional sanitization techniques (if applicable), such as a Clear or Purge technique applied following Cryptographic Erase, to ensure that the cryptographic operation completed successfully. A quick sampling verification as described in the Verify Methods subsection should also be performed after any additional techniques are applied following Cryptographic Erase.

Not all implementations of encryption are necessarily suitable for reliance upon Cryptographic Erase as a Purge mechanism. The decision regarding whether to use Cryptographic Erase depends upon verification of attributes previously identified in this guidance and in Appendix D.

Given the variability in implementation of the Enhanced Secure Erase feature, use of this command is not recommended without first referring the manufacturer to identify that the storage device's model-specific implementation meets the needs of the organization.

This guidance applies to Legacy Magnetic media only, and it is critical to verify the media type prior to sanitization. Note that emerging media types, such as HAMR media or.

hybrid drives may not be easily identifiable by the label. Refer to the manufacturer for details about the media type in a storage device.

Overwrite media by using organizationally approved and validated overwriting technologies/methods/tools. The Clear pattern should be at least a single pass with a fixed data value, such as all zeros. Multiple passes or more complex values may alternatively be used.

Four options are available:

l. Apply the SCSI sanitize command, if supported. One or both of the following options may be available:

• The overwrite command. Use three total passes of a pseudorandom pattern, leveraging the invert option so that the second pass is the inverted version of the pattern specified.

• If the device supports encryption, the Cryptographic Erase (also known as sanitize crypto scramble) command. Optionally: After Cryptographic Erase is successfully applied to a device, use the overwrite command (if supported) to write one pass of zeros or a pseudorandom pattern across the media: lfthe overwrite command is not supported, Secure Erase or the Clear rocedure could alternative! be a lied.

B-5

2. Cryptographic Erase through the TCG Opal SSC or Enterprise SSC interface by issuing commands as necessary to cause all MEKs to be changed. Refer to the TCG and vendors shipping TCG Opal or Enterprise storage devices for more information. Optionally: After Cryptographic Erase is successfully applied to a device, use the overwrite command (if supported) to write one pass of zeros or a pseudorandom pattern across the media. Ifthe overwrite command is not supported, Secure Erase or the Clear procedure could alternatively be applied.

3. If neither of the first two options is supported, use the native read and write interface to write least a single pass with a fixed data value, such as all zeros.

Multiple passes or more complex values may alternatively be used.

4. Degauss in an organizationally approved automatic degausser or disassemble the hard disk drive and Purge the enclosed platters with an organizationally approved degaussing wand.

Shred, Disintegrate, Pulverize, or Incinerate by burning the device in a licensed incinerator.

Verification must be performed for each technique within Clear and Purge as described in the Verify Methods subsection, except degaussing. The assurance provided by degaussing depends on selecting an effective degausser, applying it appropriately and periodically spot checking the results to ensure it i.s working as expected.

When using the three pass SCSI sanitize overwrite procedure with the invert (also known as complement) option, the verification process would simply search for the original pattern (which would have been written again during the third pass). While it is widely accepted that one pass of overwriting should be sufficient for Purging the data, the availability of a dedicated command that incorporates the ability to invert the data pattern allows an efficient and effective approach that mitigates any residual risk associated with variations in implementations of magnetic recording features across device manufacturers.

The storage device may support configuration capabilities that artificially restrict the ability to access portions of the media, such as SCSI mode select. Even when a dedicated sanitization command addresses these areas, their presence may affect the ability to reliably verify the effectiveness of the sanitization procedure ifleft in place. Any configuration options limiting the ability to access the entire addressable area of the storage media should be reset prior to applying the sanitization technique.

When Cryptographic Erase is applied, verification must be performed prior to additional sanitization techniques (if applicable), such as a Clear or Purge technique applied following Cryptographic Erase, to ensure that the cryptographic operation completed successfully. A quick sampling verification as described in the Verify Methods subsection should also be performed after any additional techniques are applied following Cryptographic Erase.

Not all implementations of encryption are necessarily suitable for reliance upon Cryptographic Erase as a Purge mechanism. The decision regarding whether to use Cryptographic Erase depends upon verification of attributes previously identified in this guidance and in Appendix D. This guidance applies to Legacy Magnetic media only, and it is critical to verify the media type prior to sanitization. Note that emerging media types, such as HAMR media or hybrid drives may not be easily identifiable by the label. Refer to the manufacturer for details about the media type in a storage device.

B-6

Overwrite media by using organizationally approved and validated overwriting technologies/methods/tools. The Clear pattern should be at least a single pass with a fixed data value, such as all zeros. Multiple passes or more complex values may alternatively be used.

See Destrnct. The implementation of External Locally Attached Hard Drives varies sufficiently across models and vendors that the issuance of any specific command to the device may not reasonably and consistently assure the desired sanitization result.

When the external drive bay contains an A TA or SCSI hard drive, if the commands can be delivered natively to the device the device may be sanitized based on the associated media-specific guidance. However, the drive could be configured in a vendor-specific manner that precludes sanitization when removed from the enclosure. Additionally, if sanitization techniques are applied, the hard drive may not work as expected when reinstalled in the enclosure.

Refer to the device manufacturer to identify whether the device has a Purge capability that applies media-dependent techniques (such as rewriting, block erasing, Cryptographic Erase, etc.) to ensure that data recovery is infeasible, and that the device does not sin1ply remove the file ointers.

Shred, Disintegrate, Pulverize, or Incinerate by burning the device in a licensed incinerator.

Verification as described in the Verify Methods subsection must be performed for each technique within Clear and Purge.

Some external locally attached hard drives, especially those featuring security or encryption features, may also have hidden storage areas that might not be addressed even when the drive is removed from the enclosure. The device vendor may leverage proprietary commands to interact with the security subsystem. Please refer to the manufacturer to identify whether any reserved areas exist on the media and whether any tools are available to remove or sanitize them, if resent.

NI A, see Destrnct.

Destroy in order ofrecommendations:

1. Removing the information-bearing layers of CD media using a commercial optical disk grinding device. Note that this applies only to CD and not to DVD or BD media

2. Incinerate optical disk media (reduce to ash) using a licensed facility.

3. Use optical disk media shredders or disintegrator devices to reduce to particles that have a nominal edge dimensions of point five millimeters (.5 mm) and surface area of oint two five s uare millimeters .25 mm2) or smaller.

Overwrite media by using organizationally approved and validated overwriting technologies/methods/tools. The Clear pattern should be at least a single pass with a fixed data value, such as all zeros. Multiple passes or more complex values may alternatively be used.

2. Leverage (the non-enhanced) AT A Secure Erase, if supported by the device.

B-7

1bree options are available:

I. Apply the ATA sanitize command, if supported. One or both of the following options may be available:

• The block erase command. Optionally: After the block erase command is successfully applied to a device, write binary ls across the user addressable area of the storage media and then perform a second block erase.

• If the device supports encryption, the Cryptographic Erase (also known as sanitize crypto scramble) command. Optionally: After Cryptographic Erase is successfully applied to a device, use the block erase command (if supported) to block erase the media. If the block erase command is not supported, Secure Erase or the Clear procedure could alternatively be applied.

2. Apply the ATA Secure Erase command. The sanitize command is preferred to Secure Erase when the sanitize command is supported by the device.

3. Cryptographic Erase through the TCG Opal SSC or Enterprise SSC interface by issuing commands as necessary to cause all MEKs to be changed. Refer to the TCG and vendors shipping TCG Opal or Enterprise storage devices for more information. Optionally: After Cryptographic Erase is successfully applied to a device, use the block erase command (if supported) to block erase the media. If the block erase command is not supported, Secure Erase or the Clear procedure could alternative! be a lied.

Shred, Disintegrate, Pulverize, or Incinerate by burning the device in a licensed incinerator.

Verification must be performed for each technique within Clear and Purge as described in the Verify Methods subsection.

When Cryptographic Erase is applied, verification must be performed prior to additional sanitization techniques (if applicable), such as a Clear or Purge technique applied following Cryptographic Erase, to ensure tbat the cryptographic operation completed successfully. A quick sampling verification as described in the Verify Methods subsection should also be performed after any additional techniques are applied following Cryptographic Erase.

The storage device may support configuration capabilities that artificially restrict the ability to access portions of the media as defined in the ATA standard, such as a Host Protected Area (HPA), Device Configuration Overlay (DCO), or Accessible Max Address.

Even when a dedicated sanitization command addresses these areas, their presence may affect the ability to reliably verify the effectiveness of the sanitization procedure if left in place. Any configuration options limiting the ability to access the entire addressable area of the storage media should be reset prior to applying the sanitization technique. Recovery data, such as an OEM-provided restoration image may have been stored in this manner, and sanitization may therefore impact the ability to recover the system unless reinstallation media is also available.

Not all implementations of encryption are necessarily suitable for reliance upon Cryptographic Erase as a Purge mechanism. The decision regarding whether to use Cryptographic Erase depends upon verification of attributes previously identified in this guidance and in Appendix D.

Given the variability in implementation of the Enhanced Secure Erase feature, use of this command is not recommended without first referring the manufacturer to identify that the storage device's model-specific implementation meets the needs of the organization.

Whereas AT A Secure Erase was a Purge mechanism for magnetic media, it is only a Clear mechanism for flash due to variabili lementation and the ossibility that sensitive

B-8 data may remain in areas such as spare cells that have been rotated out of use. Degaussing must not be solely relied upon as a sanitization technique on flash-based storage devices or on hybrid devices that contain non-volatile flash storage media.

Degaussing may be used when non-volatile flash media is present ifthe flash components are sanitized using media-dependent techniques.

Overwrite media by using organizationally approved and validated overwriting technologies/methods/tools. The Clear pattern should be at least a single pass with a fixed data value, such as all zeros. Multiple passes or more complex values may alternatively be used.

Two options are available:

l. Apply the SCSI sanitize command, if supported. One or both of the following options may be available:

• The block erase command.

• If the device supports encryption, the Cryptographic Erase (also known as sanitize crypto scramble) command.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .