Below is a high-level comparison of media sanitization and the legal concept of the reasonableness standard, intended for technical and business leaders. It is not legal advice and is not a substitute for counsel.
Organizations face mounting challenges in protecting sensitive information, and one of them is the proper disposal of electronic media, which if handled improperly leads to breaches and legal consequences. NIST Special Publication 800-88 provides the guidelines for media sanitization. At the same time, legal frameworks evaluate organizational decisions against a standard of reasonableness: whether an action was appropriate given the circumstances. This post explores the connection between the two and how to align them.
What NIST 800-88 media sanitization is
NIST 800-88, Guidelines for Media Sanitization, is a comprehensive framework for securely erasing data from electronic storage media. It provides techniques that depend on the type of media and the level of security required, in three methods:
- Clear: overwriting data on the device so it is difficult to recover. Suitable when the device will be reused inside the organization, not for sale or reuse by others.
- Purge: techniques that remove data beyond recovery by standard forensic tools, often used for devices being decommissioned but still functional. Media-specific, and Revision 2 points to IEEE 2883 for the right technique.
- Destroy: physically destroying the media by shredding, disintegrating, or incinerating so the data is permanently unrecoverable.
The methods accommodate different security needs. NIST 800-88 also provides a decision flow to guide the choice.
The reasonableness standard in law
In legal terms, the reasonableness standard requires organizations to take actions that are reasonable under the circumstances. It comes into play when determining whether an organization took appropriate steps to prevent harm, particularly in privacy and security cases. In data security, it means implementing appropriate safeguards and responding reasonably when threats arise.
Courts weigh the nature of the data, the potential harm from a breach, and the organization's resources, and they look at industry standards, best practices, and legal obligations to decide whether the organization met the standard.
Where the two meet
- Data sensitivity and risk assessment. NIST 800-88 recommends different levels of sanitization for different data; the reasonableness standard expects the same proportionality. Health or financial records call for more rigorous methods than public data.
- Cost and proportionality. NIST 800-88 offers options of varying intensity. Physical destruction is the most secure and can cost more; Clear or Purge may be reasonable for low-risk data with other controls in place. The law does not demand excess, but it does demand that the choice match the risk.
- Industry standards. Courts and regulators assess adherence to recognized guidelines. Adopting NIST 800-88 as your framework is direct evidence that you followed accepted practice.
- Documentation and accountability. NIST 800-88 requires records of methods, devices, and personnel. The reasonableness standard requires you to demonstrate what you did. The same documentation serves both.
Balancing legal risk and technical practice
- Perform risk assessments and have leadership communicate the security categorization for each class of data, so the people making sanitization decisions can apply NIST 800-88 correctly.
- Document decisions and actions. NIST 800-88 says what to record. Record it.
- Update the disposal policy regularly. Technology and guidance move. NIST, the NSA, and allied governments have all published concerns about the risk quantum computing poses to encryption in common use today. The reasonableness standard rewards organizations that stay current and eventually punishes those that do not.
- Train the staff who handle media, from a written policy developed by technical experts and approved by leadership.
- Understand your ITAD vendor's business model. The IT asset disposition industry has different revenue structures. Some vendors are paid primarily by reselling your hardware online to the highest bidder. Others specialize in high-security environments and are paid to destroy it. Both can claim to be "NIST 800-88 compliant," because the standard allows Clear, Purge, and Destroy. Your organization is responsible for the data entrusted to it, and that liability cannot be transferred to a vendor. Review the vendor's specific methods and ask what happens to a drive that fails verification. Only then can you judge whether the vendor fits the sensitivity of your data. The Morgan Stanley case is what the alternative looks like.
Conclusion
NIST 800-88 and the reasonableness standard reinforce each other. Organizations have a legal obligation to protect sensitive data, that obligation cannot be transferred to a vendor, and NIST's guidelines are the recognized standard for meeting it. Develop your own sanitization policy in alignment with NIST 800-88, in the context of the regulations you fall under (HIPAA, CJIS, GLBA, CMMC), and you will protect both your data and your position.
This document is not legal advice and is not a replacement for proper legal counsel.
Written by Christopher McDevitt with AI assistance.
