Most of the case studies on this site are about failures at other organizations. This one is about an ordinary day of ours, because the ordinary day is the product. The City of Mansfield is a repeat client; its IT department retires hardware in batches from a storage room, and because city systems touch criminal justice information, every batch is handled to the FBI CJIS Security Policy. The job below is drawn from the certificate and media log we issued in May 2026.
What arrived
Eighty-seven assets, staged in a storage room: desktop and small-form-factor PCs, a handful of consumer machines that had been turned in, and a mix of the drives inside them. Each carried a city asset tag, which became the first column of the log. The media inside was a cross-section of a municipal fleet: 3.5-inch and 2.5-inch hard drives from Seagate and Western Digital, SATA SSDs from Crucial and others, and Microsoft Surface devices with soldered storage.
How the day ran
- Inventory by asset tag. Every chassis was logged against the city's tag before it was opened, so the certificate would reconcile to the city's property records line for line.
- Open, identify, record. Each device was opened and its storage identified by make, part number, and serial. Where a device held no drive at all, the log says so: \u201cnone found.\u201D Several did. That entry is the proof that the chassis was inspected rather than assumed empty, and it is the entry the Inspector General found missing at the FBI\u2019s own destruction facility.
- Two machines, by media type. Magnetic drives crossed the LM-1 degausser and went into the shredder. Solid-state drives and the Surface devices went to the GigaBiter GB12 and came out as particles smaller than 2 mm. The equipment column names which.
- Two technicians, one witness. Every row carries both technician IDs. The city\u2019s representative approved the release of each asset, watched the destruction, and is named on the log as the customer approval, which is what CJIS means by authorized personnel.
- Certificate, same day. The signed letter, stating the standard achieved, and the media log with all eighty-seven rows were issued with the same date as the destruction. The destroyed material went to a named R2-certified recycling partner, recorded on the log.
Why it matters for a city
Ohio HB 96 requires every political subdivision to run a cybersecurity program consistent with recognized best practices, and the disposal of retired hardware sits inside that program. The CJIS Security Policy requires that media holding criminal justice information be disposed of by authorized personnel with a record of it. A day like this one satisfies both with a single document set: the city\u2019s own staff witnessed the destruction of every device, and the log ties every serial number to a method, a machine, a date, and a name.
It also cost the city nothing in staff time beyond the walk to the storage room. The alternative, wiping eighty-seven machines one at a time and hoping the software reached every sector, would have taken days and produced a log that proves less.
What we would tell another municipality
- Tag it, then count it. The asset tag is the unit of accountability until the drive comes out; then the serial is.
- Do not stage. Retired machines in a storage room are a question. Book the destruction for the week they come out of service.
- Insist on the empty-chassis entry. A log that lists only drives cannot prove which computers were checked.
- Keep the certificate with the HB 96 program documentation. It is the artifact that closes the disposal item.
See the certificate and media log this job produced, with the client redacted, or how we work with governments.
Published with the City of Mansfield\u2019s knowledge as a past-performance reference. Written by Christopher McDevitt with AI assistance.
