Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISN] NIST experts craft data removal handbook |
|---|---|
| Date: | Wed, 8 Feb 2006 02:19:51 -0600 (CST) |
http://www.washingtontechnology.com/news/1_1/daily_news/27920-1.html By Joab Jackson Contributing Staff Writer 02/07/06 Wonder no longer about how to remove sensitive data from the hard drives and optical disks you are about to toss. The National Institute of Standards and Technology has issued a set of draft guidelines on how to safely remove information from obsolete forms of storage. Matthew Scholl, Richard Kissel, Steven Skolochenko and Xing Li of the NIST Information Technology Laboratory authored Special Publication 800-88 [1], "Guidelines for Media Sanitization: Recommendations of the National Institute of Standards and Technology," which was sponsored by the Homeland Security Department. "When storage media are transferred, become obsolete or are no longer usable or required by an information system, it is important to ensure that residual magnetic, optical or electrical representation of data that has been deleted is not easily recoverable," the guidelines stated. Although the publication summarizes the ways to remove data, it emphasizes that a proper disposal methodology should not be based on the type of storage being disposed, but rather on the confidentiality of the material the medium contains. The authors conclude that there are three general approaches to excising data from various storage technologies: Clearing: This approach usually involves overwriting the data with new random data, or in cases of electronic devices, deleting existing information and performing a manufacturer's hard reset (if one exists). Purging: This approach involves "degaussing" the medium, a procedure that involves generating a magnetic field to neutralize the magnetically encoded information. The report notes that the new Serial ATA hard disk drives have a firmware-based Secure Erase command that can purge information to the same degree of unrecoverability. Destroying: The form of destruction depends on the type of media being used. Shredding could work for paper, while pulverization, melting and incineration (tasks usually outsourced) would be more appropriate for hard disks or optical disks. Sanding off the physical recording surface is another option. The report also shows how to apply these approaches to various technologies such as personal digital assistants, routers, copy machines, hard drives and floppy disks. NIST also urged organizations to establish enterprise governance procedures for erasing material from old technologies. "Ultimately, the head of the organization is responsible for ensuring that adequate resources are applied to the program and for ensuring program success," the report noted. "Senior management is responsible for ensuring that the resources are allocated to correctly identify types and locations of information and to ensure that resources are allocated to properly sanitize the information." [1] http://csrc.nist.gov/publications/drafts/DRAFT-sp800-88-Feb3_2006.pdf _________________________________ InfoSec News v2.0 - Coming Soon! http://www.infosecnews.org
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] Honeywell blames ex-employee in data leak, InfoSec News |
|---|---|
| Next by Date: | [ISN] 'Sleeper bugs' used to steal .1m in France, InfoSec News |
| Previous by Thread: | [ISN] Honeywell blames ex-employee in data leak, InfoSec News |
| Next by Thread: | [ISN] 'Sleeper bugs' used to steal .1m in France, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |