NSA Compliant Hard Drive Destruction
The National Security Agency and Central Security Services (NSA/CSS) has put together a manual entitled NSA/CSS Storage Device Sanitization Manual 9-12 to address destruction requirements for each type of digital media. The manual details acceptable equipment and methodology for hard drive destruction.
All NSA/CSS elements, contractors and personnel must adhere to the NSA/CSS Storage Device Sanitization Manual 9-12 when it comes time to dispose of digital media including hard drives, SSDs, magnetic backup tapes and CDs in their possession.
Sanitization and Destruction Methods
NSA/CSS Storage Device Sanitization Manual 9-12 says the following hard drive destruction techniques are acceptable for DoD and NSA compliance. Devices used for destruction must be on the NSA/CSS Evaluated Products List. There basically two options for NSA/CSS hard drive destruction in California – deguass and destroy or disintegrate. Since California has banned incineration of electronics, it is not an option.
Degauss & Destroy
Most NSA contractors prefer to degauss and destroy hard drives. The advantages of deguassing and destroying hard drives over disintegration is that it is more efficient and environmentally friendly. Disintegration is required only for flash memory such as SSDs and cell phones.
Deguassing and destroying a single 3.5” server hard drive takes less than 7 seconds. Disintegrating an SSD to the 2mm requirement should take 10 minutes.
Solid state drives (SSDs) cannot be degaussed because they do not store data on magnetic media. As such, NSA/CSS requires that SSDs and other flash media be disintegrated into 2mm particles. This ensures that every chip on the flash drive is destroyed and data is not recoverable.
Most organizations that fall under NIST 800-88, HIPAA and PCI data destruction require that SSDs and other flash media be shredded to .375” (9.5mm). This size shred ensures that all chips are destroyed.