CISSP Certification Guide / Chapter 10
Retention, Handling, and Disposal
The three decisions at the end of the asset lifecycle: how long data is kept, how it is handled while it exists, and how completely it stops existing. Retention drivers from SOX to the GDPR, the retention schedule and the litigation hold, data remanence, the NIST SP 800-88 clear/purge/destroy sanitization ladder, method against media, crypto erase, and disposal in the cloud.
The asset’s last mile
A server that held customer records for six years is being decommissioned. Three questions decide whether that server leaves the building as an asset or as a liability. First: how long were we permitted to keep its data, and is that period over? Second: how was the data handled while it lived on that machine, and can we account for every copy that left it? Third: when the drive leaves, what actually remains on the platters?
This chapter is the answer to those three questions, and the CISSP puts them in Domain 2 because they are asset decisions, not plumbing. Retention is a risk decision about how long the organization carries the liability that the data represents. Handling is the discipline that keeps an asset identified, protected, and accounted for while it is held. Disposal is the decision about how completely the asset’s information content stops existing, on the original media and on every copy. The three share a single shape: each one ends in a documented decision made by someone accountable, and each one is worthless if the paperwork does not exist.
The exam tests this material through the manager lens, which means it rarely asks you to name a shredder model. It asks you to decide. Given a class of records, how long are they kept and who decides? Given a drive with data of a certain classification, which sanitization category is enough, and which technique fits the media? Given a cloud account, what does “deleted” actually mean, and which party is responsible for which part of destruction? This chapter gives you the decision framework for all three, and the practice questions at the end push the framework until it is reflex.
What retention is for
Retention is not hoarding. A retention program exists to answer one question with a schedule instead of with guesswork: how long does each class of information exist in the organization? The answer has three ingredients, and the exam expects you to know that all three must be present before a period is defensible.
The first ingredient is the legal and regulatory minimum. When a law or a regulator sets a floor, the floor is binding. The SEC’s rules under the Sarbanes-Oxley Act require public-company accounting firms to retain audit work papers for seven years after the conclusion of the audit (SEC Rule 210.2-06). HIPAA requires covered entities and business associates to retain the documentation of their policies and procedures, and of their privacy and security actions, for six years from creation or last use (45 CFR 164.316(b)(2) under the Security Rule, with the same period at 45 CFR 164.530(j) for Privacy Rule documentation). PCI DSS v4.0 requires entities that process cardholder data to retain audit log history for at least twelve months, with the most recent three months immediately available for analysis (Requirement 10.5.1). Federal agencies keep records according to schedules approved by the National Archives and Records Administration. These are floors: the retention schedule must meet or beat them, never dip below.
The second ingredient is business value. A warranty claim can surface four years after a sale. A tax audit can reach back seven. An intellectual-property dispute can hinge on an engineering notebook nobody planned to keep. Business need is real, and it is evidence, but it is not infinity. The organization should be able to say, for each record class, what the data is still worth, to whom, and until when. A retention period that is justified only by “we might need it someday” is a cost and a risk, not a policy.
The third ingredient is the minimization constraint, which is the ceiling that law and principle put on the floor. Article 5(1)(e) of the GDPR states the storage limitation principle: personal data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which it is processed. The GDPR does not say “delete as soon as possible”; it says the retention must be necessary, purpose-tied, and defensible. Article 17 gives data subjects the right to erasure, which means the organization must be able to find and delete an individual’s data on demand, not merely agree to stop using it. PCI DSS v4.0 Requirement 3.2.1 tells the same story from the other direction: retention of stored account data must be limited to what is required for legal, regulatory, or business requirements, with a defined retention period that is as short as practical, and Requirement 3.2.2 demands that data past its retention point be securely deleted on a routine cycle, at least quarterly. Over-retention is a liability: every extra month of stored data enlarges breach scope, discovery scope, storage cost, and regulator attention.
This two-sided shape matters because it is the exam’s favorite trap. A question offers a retention answer that is too short, violating the floor, or too long, violating the ceiling, or exactly right: the longest applicable legal requirement, trimmed by the minimization principle, documented in an approved schedule. The right answer is the scheduled one.
The retention decision framework
Retention decisions do not happen once. They happen continuously, for every record class, on a schedule, and the framework has six steps.
Step one: know the record class. This is Chapter 8 doing its job. The asset inventory names the data, classification assigns the impact, and the retention schedule assigns the period. A record class with no owner and no label cannot be scheduled, and an unscheduled record class is either deleted on a whim or kept forever, both failures.
Step two: find the most demanding applicable legal or regulatory minimum. Where multiple requirements overlap, the longest floor governs. An audit record that is both a HIPAA documentation item and a tax record inherits the longest period. The rule is: never retain less than the strictest applicable requirement.
Step three: add the business justification, with an owner and an end date. The warranty period, the contract term, the limitation period for disputes, the industry practice. Business value extends the period; it does not make it indefinite.
Step four: apply the minimization ceiling. Personal data stays in identifiable form only as long as the purpose requires, per GDPR Article 5(1)(e). Cardholder data is deleted no later than the quarterly cycle per PCI DSS v4.0 Requirement 3.2.2. The schedule states both the floor and the ceiling, and the gap between them is where the organization actually lives.
Step five: check for a hold. A litigation hold, a regulatory hold, or an investigation hold is the master switch: the moment litigation is reasonably anticipated, scheduled destruction of relevant records stops. This is not optional politeness. Destroying records that a pending or foreseeable legal matter could demand is spoliation, and it converts a routine disposal into an independent wrong that courts and regulators punish out of proportion to the underlying case. The hold overrides the schedule for the records it covers, and it ends only when the matter resolves or the responsible attorney lifts it.
Step six: record the decision and review it. The retention schedule is a management-approved, versioned document. Disposition events are logged: what was destroyed, by which method, on what date, with whose sign-off. When a law changes, when a contract expires, when an acquisition lands a new record set, the schedule is re-reviewed. A schedule that sits in a drawer for a decade is not a program.
The exam tests this ladder in two directions. Forward: given a record class and a scenario, what period applies. Backward: given a failure, which step broke. A company that deletes everything after three years regardless of the tax floor broke step two. A company that keeps everything forever “to be safe” broke step four. A company that purged e-mails the day after a lawsuit was filed broke step five. The pattern is always the same: the schedule is the control, the hold is the emergency brake, and the documentation is the proof.
Handling: how the asset travels
Retention says how long data exists. Handling says how it moves while it exists, and the exam treats handling failures as disposal incidents that happen early. A laptop with unencrypted customer data that goes missing from a train is not a disposal story; it is a handling story with the same consequences as a botched destruction, and the manager reasoning is identical: the asset was not protected in its custody phase, so it became a breach in its transit phase.
The handling controls are the ones Chapter 8 introduced as asset protections, now pointed at media and records. Marking: each medium carries the classification of its contents, so a person handling a tape knows what it holds without opening it. Inventory: the organization can say where each removable medium is, who last touched it, and what it contains, which is what makes an audit of media possible and what makes loss detectable. Access: only authorized handlers can check media out, and custody transfers are logged. Transport: removable media leaving the facility travels encrypted, in tamper-evident packaging, by a tracked method, with the custody chain recorded. Environment: magnetic and optical media need protection from heat, humidity, and physical damage while stored. Use: the removable media policy controls what kinds of data may be copied to portable devices at all, and how, which is where USB ports are locked down and where encryption of portable media is mandated.
Two standards anchor this discipline. ISO/IEC 27001:2022 places storage media management under Annex A control 7.10, which requires rules for the management of removable media: permitted types, usage restrictions, inventory, and disposal. NIST SP 800-53 Revision 5 organizes the same material as the MP family: media marking, media storage, media transport, media use, and media sanitization. The names differ, the intent is one: the organization knows what its media hold, who has them, and how they are allowed to move.
The exam question that tests handling is usually a scenario with a missing step. The company ships backup tapes to a disaster site; the answer is encrypted transport with tamper evidence and a custody log. The company loses a laptop; the question asks which control would have prevented the breach, and the answer is full-disk encryption plus inventory and access control, not a better shredder. Handling is the middle gear of this chapter: retention decides how long, handling decides how safely, disposal decides how completely.
Remanence: why delete is not gone
Before any sanitization method makes sense, one fact has to be internalized, because it is the entire reason this chapter exists. Deleting a file does not remove the data. On a conventional disk, deletion removes the directory entry and marks the space as available; the bytes remain on the platter until something overwrites them. The same is true in more places than the exam candidate expects.
Data remanence is the residual physical representation of data after it has been nominally erased or overwritten. The classic surfaces are unallocated space, the area the file system considers free, and slack space, the unused tail of the last allocated sector. Beyond those, residue lives in the swap file, the hibernation file, temporary files, application caches, browser history, log files, and the sectors a drive marks as bad and quietly stops reporting. On solid-state media the problem is worse: wear leveling writes new data across the whole device, garbage collection relocates pages in the background, and over-provisioned spare cells hold copies of data the user thought was gone. Even volatile memory retains data for a short time after power loss, which is why the physical-attacker model treats a powered-down machine as a recovery target rather than a blank slate.
The consequence for the manager is a change of frame. Disposal is not judged by what the user sees after deletion; it is judged by what an attacker with tools can recover, and the standard is a level of effort. That is precisely how NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization, defines its subject: sanitization is a process to render access to target data on the media infeasible for a given level of effort. The level of effort is the dial. The next section is the ladder that turns that dial up.
Sanitization per NIST SP 800-88 Rev. 1
NIST SP 800-88 Rev. 1 is the reference standard for media sanitization, and the exam expects you to know its ladder of three categories: clear, purge, and destroy. Each category is defined by the level of effort needed to recover the data after the process, and the choice between them is driven by two variables: the confidentiality impact of the data and the type of media.
Clear is the lowest category. It applies logical techniques to sanitize data in all user-addressable storage locations, and it is designed to protect against simple, non-invasive data recovery techniques, the kind an ordinary person with file-recovery software can do. Clearing is typically done by overwriting with standard read and write commands or by resetting a device to its factory state. Clear is the right answer when media stays inside the organization for a less sensitive role: the drive is being reused, not released, and the audience that must be kept out is casual, not equipped.
Purge is the middle category. It applies physical or logical techniques that render target data recovery infeasible using state-of-the-art laboratory techniques, the kind a forensic facility or a well-funded adversary can do. Purging is typically done with dedicated, standardized device sanitize commands such as ATA Secure Erase, with degaussing for magnetic media, with a properly executed cryptographic erase, or by destroying the media outright. Purge is the bar for media that leaves the organization’s control: sold, donated, returned to a lessor, or sent to a third party. Clear’s overwrite is not enough there, because the recoverer may have laboratory tools.
Destroy is the top category. It renders target data recovery infeasible using state-of-the-art laboratory techniques and makes the media unusable for storage afterward. The techniques are physical: shredding, disintegration, pulverizing, melting, and incineration. Destroy is the answer for the highest confidentiality data, for media types that cannot be reliably purged by logical means, and whenever the organization’s risk appetite says that even the possibility of laboratory recovery is unacceptable.
The standard then demands two things the exam loves. First, the decision must be based on the confidentiality of the information and the media type, which in practice means the FIPS 199 confidentiality impact category of the data on the medium: low, moderate, or high. A tape of moderately sensitive data leaving the organization calls for purge; a tape of high-impact data calls for destroy. Second, sanitization must be verified. The process is not complete when the overwrite finishes or the shredder runs; it is complete when someone confirms the data cannot be accessed, by attempting to read the media and checking for residual data, and records the result. Sanitization logs, sign-offs, and certificates of destruction are the control’s paper trail, and the exam treats their absence as the control’s absence.
One piece of folklore deserves an explicit burial, because it appears in outdated material and in exam-room memory. The three-pass and seven-pass overwrite formulas from the old Department of Defense manual are superseded; NIST’s current guidance is that a single overwrite pass with a fixed pattern, such as binary zeros, is adequate to clear modern ATA drives. More passes do not linearly improve results against modern recovery, because the recovery methods overwriting defeats are not defeated by repetition. The pass count is not the point; the category, the media type, and the verification are.
Method against media
The exam’s sharpest disposal questions give you a medium and ask which method fits, or give you a method and ask which media it destroys. The matrix is short, and every cell is testable.
Hard disk drives are the baseline. They are magnetic and they support standard read and write commands, so all three categories are available: clear by overwriting, purge by ATA Secure Erase, degaussing, or crypto erase, and destroy by shredding or disintegration. Overwrite works on HDDs because the sectors the file system addresses are the sectors that hold the data.
Solid-state drives are the trap cell. Overwriting does not reliably clear an SSD, because the drive’s firmware does not let the operating system address every cell: wear leveling distributes writes across the device, garbage collection relocates and erases pages on its own schedule, and over-provisioned spare cells hold data the user can never reach with a normal write. The reliable answers for an SSD are ATA Secure Erase, which invokes the drive’s own firmware sanitize routine, crypto erase where the device was encrypted, and physical destruction for high-impact data. A question that offers “overwrite with zeros” for an SSD is offering a wrong answer, and so is a question that offers degaussing.
Degaussing is the second trap cell. It works by exposing media to a strong magnetic field that randomizes the magnetic domains, and it works only on magnetic media: HDDs, tapes, floppy disks. It does nothing to an SSD, which stores charge in flash cells rather than magnetic orientation, and nothing to optical media. On magnetic media it is thorough: it erases data and servo tracks together, which means the drive is unusable afterward. That is not a bug; degaussing is a purge or destroy-class event for magnetic media, and it is the standard answer for tapes that must never be read again.
Optical media, CDs, DVDs, and Blu-ray, are not magnetic and cannot be degaussed or meaningfully overwritten. They are destroyed by shredding or incineration, and the destroy category is the realistic default because laboratory recovery from optical media is a known technique.
Paper joins the matrix through disposal rules rather than firmware. Cross-cut shredding, incineration, and pulping are the accepted methods, and the FTC’s Disposal Rule under the Fair and Accurate Credit Transactions Act (16 CFR Part 682) requires reasonable measures to protect against unauthorized access to consumer report information in and after disposal, which is the regulator’s way of saying that paper with consumer data gets shredded or burned, not recycled whole.
Volatile memory is handled by powering down, with the caveat that recent DRAM retains its contents briefly after power loss, so a machine holding high-impact secrets should be shut down deliberately rather than left to crash, and memory encryption is the control of choice where the threat demands it. Mobile devices follow the SSD logic: full-disk encryption plus destruction of the key material, then a factory reset, with physical destruction for high-impact contents, and removal of SIM and storage cards so they are disposed of as separate media.
The rule that ties the cells together is the one NIST makes: the method follows the media type and the confidentiality impact. A method that is perfect for one medium is useless or harmful for another, and the exam scenario that mixes media is the one where candidates panic. The answer is always the per-media cell, never a universal technique.
Crypto erase: the elegant exit
Crypto erase deserves its own movement because it is the most elegant tool in the kit and the easiest to misuse. The idea is simple. If data at rest is encrypted with a strong key, and that key is destroyed, then the ciphertext that remains is effectively unrecoverable: without the key, recovering the plaintext is computationally infeasible, which is exactly the definition of purge. NIST SP 800-88 Rev. 1 accepts cryptographic erase as a purge technique, and the modern world leans on it heavily, because it is fast, it works on media that resist overwriting, and it costs nothing in hardware.
The exam, however, tests the conditions, and the conditions are strict. Crypto erase is only valid when the encryption was real, which means a validated cryptographic module, in practice one meeting the FIPS 140-2 or FIPS 140-3 validation program requirements. It is only valid when the encryption covered the data: the whole disk including swap, temp, and hibernation areas, not just a few files in a protected folder. And it is only valid when the key is truly gone: no escrowed copy, no backup copy, no recovery copy, no replication in a cloud key service, no paper printout in a safe.
The failure modes are the exam’s answer choices. An organization encrypts its laptops, then stores recovery keys in an escrow service so help desk staff can unlock them; crypto erasing the laptops by deleting the local key changes nothing while the escrow copy survives. A cloud customer deletes the volume key but keeps an old key version alive because the key service retains deleted key material for a window; the encryption is intact and the data is still reachable. A team encrypts the data partition but leaves the boot partition and the swap file in the clear; destroying the key leaves a recoverable fragment behind. Every one of these is a scenario where the elegant exit turns out to be a corridor back into the room.
The manager takeaway is a test question the candidate can ask of any crypto-erase plan: what would it take for someone to recover the plaintext, and where are the copies of the key? If the honest answer requires deleting key copies in three places, then the plan has three deletion steps, and the schedule says when each one runs. Crypto erase is a purge-level control when those answers are clean, and a theater prop when they are not.
Disposal in the cloud
Cloud disposal is where the framework meets the shared responsibility model, and it is the section where the exam separates the candidate who understands abstraction from the candidate who memorized a shredder. On-premises, the organization owns the media and can physically destroy it. In the cloud, the organization rents capacity on media it cannot see, so “disposal” becomes a bundle of logical operations, key operations, and contractual commitments, and physical destruction is performed by the provider on its own decommissioning cycle.
The first thing to unlearn is the word “delete”. Deleting an object in an object store removes the pointer; it does not immediately erase the bytes, and it certainly does not touch the copies that live elsewhere. Cloud data multiplies without being asked: object versions, block storage snapshots, automated backups, cross-region replicas, database transaction logs, and monitoring data all hold the same information in different forms. The classic failure is the team that “deleted the database” while a scheduled snapshot from last night still contains everything, or the team that deleted the current object version while the previous version, the one with the customer data, survives in the version history. Disposal in the cloud is therefore an inventory exercise first: list every place the data exists, then delete each one, then check again.
The mechanics are the same mechanics as on-premises, expressed as cloud controls. Lifecycle policies expire objects and old versions on a schedule, which is the retention schedule operating in the platform. Versioning is controlled so that deletion is not resurrection. Deletion of volumes, clusters, and buckets is done with attention to their final snapshot settings. Key destruction is the crypto-erase leg: encrypted volumes are rendered unrecoverable when their key material is scheduled for deletion, which is why cloud key services implement waiting periods measured in days, commonly 7 to 30, before a key is actually gone, and why the deletion must be confirmed after the window closes. MFA-protected deletion exists so that a compromised console session cannot silently erase the evidence and, equally, so that a routine cleanup cannot be weaponized by an attacker.
The responsibility split is the exam’s favorite question. The customer is responsible for logical deletion, for destroying or expiring key material, for emptying the places the data was copied, and for verifying that the deletion happened. The provider is responsible for physical destruction of the underlying media when it is decommissioned, and it evidences that through its documented processes and its compliance attestations: ISO/IEC 27001 certifications, SOC 2 reports, and, for government workloads, FedRAMP authorizations all cover media sanitization and decommissioning in their scope. The customer does not shred the provider’s drives, and the provider does not manage the customer’s object versions. The contract is where the two meet: the data processing agreement should state what the provider deletes, when, and how it will certify it.
The contract leg is not boilerplate. Article 28(3)(g) of the GDPR requires the processor’s contract to oblige it to delete or return all personal data after the end of the services, and to delete existing copies unless the law requires storage. That single clause is why the cloud disposal answer always includes the data processing agreement: in the cloud, “destroy” is partly a contract term. The customer’s disposal evidence is the deletion log, the key-deletion confirmation, the provider’s certification of destruction, and the audit right to verify, all of which belong in the same paper trail as the on-premises shredder certificate.
The decision framework in action
Work one decommissioning end to end, because this is the exam in miniature. A mid-size organization is retiring its customer-facing systems and must dispose of: a database server with HDDs holding moderately classified transaction data, fifty laptops with full-disk encryption holding high-impact customer data, a shelf of backup tapes, a room of paper HR files, and a cloud bucket of customer data with versions and snapshots.
Retention runs first. The records manager pulls the schedule: transaction data is held seven years for tax reasons, HR files follow the jurisdiction’s employment and medical record requirements, audit logs follow PCI DSS v4.0’s twelve-month floor, and none of it is under a litigation hold, because legal confirmed that no matter is pending or reasonably anticipated. The schedule is current, which is itself a control: a team that skips this step is deciding the fate of records without knowing what law or hold applies.
Handling is verified in the same pass. The media inventory says what each tape contains and where each laptop went. The tapes are labeled with their classification, the laptops are encrypted, the paper files are in a locked, access-controlled room. The inventory is what makes the rest of the operation possible, because a disposal you cannot enumerate is a disposal you cannot prove.
Sanitization is selected per medium and classification. The HDDs, moderate impact, are being decommissioned, not reused, so the decision lands at purge: ATA Secure Erase on each drive, with a verification pass that attempts to read the drives and confirms no recoverable data. The laptops, high impact, get the crypto-erase route: the full-disk encryption keys are confirmed to exist only in the laptop TPMs and the central key store, the key store entries are revoked and deleted, the recovery and escrow copies are destroyed, and each laptop is factory reset, with the TPM cleared, before it is sold through the certified refurbisher. The tapes are high impact and magnetic, so they are degaussed on a validated unit and then shredded by the destruction vendor, which issues a certificate of destruction with serial numbers. The paper HR files are cross-cut shredded in a locked room, or sent to the same vendor under a chain-of-custody manifest, because the FTC Disposal Rule applies to consumer information wherever it lives. The cloud bucket is handled as its own inventory: versions are disabled, lifecycle rules expire remaining objects, snapshots and automated backups are deleted and their retention windows confirmed, the customer-managed keys are scheduled for deletion and the completion confirmed after the window, and the provider’s data processing agreement and its media-destruction attestations are pulled into the record alongside a deletion report the storage team generates and signs.
One document ties it together. The disposal log lists every medium, its classification, the method applied, the date, the verifier, and the sign-off, and it is retained itself according to the schedule. That log is the control: it is what the auditor asks for, what the regulator asks for, and what the exam is really asking about when a scenario ends with “and now, how do we prove it”.
A set of heuristics will keep you oriented on the real exam:
- When a question offers retention answers, find the driver: the legal floor, the business need, or the minimization ceiling. The answer is the scheduled period that respects all three.
- When a hold exists, destruction stops. Litigation hold beats every retention schedule, and destroying held records is spoliation.
- When a question names a medium, name the method. Overwrite for HDDs, never for SSDs. Secure erase or destroy for SSDs. Degauss only for magnetic media. Destroy optical and paper.
- When a question says “deleted”, assume the bytes remain. Disposal is sanitization plus verification, not deletion plus hope.
- When a question offers crypto erase, check the key. Escrowed keys, backup keys, old key versions, and partial encryption all defeat it.
- When a question is about the cloud, split responsibility. The customer deletes logically, destroys keys, and verifies. The provider destroys media and evidences it through attestations and contracts.
- When a question ends with proof, the answer is documentation: sanitization logs, certificates of destruction, deletion confirmations, and sign-offs.
Practice questions
- A records manager is setting a retention period for a class of financial records. A regulation requires five years, the tax authority requires seven, the business says it needs two, and litigation that could touch the records is reasonably anticipated. What governs the period?
A. Five years, because the business needs only two and the regulation is the strictest business rule B. Seven years, with the anticipated litigation suspending any destruction of relevant records C. Two years, because business need is the deciding factor D. The shortest period that satisfies any requirement, to minimize storage cost
- Under Article 5(1)(e) of the GDPR, personal data must be kept in a form that permits identification of data subjects for how long?
A. For the period the data controller’s storage infrastructure allows B. For no longer than is necessary for the purposes for which the data is processed C. For the longest period any law in any jurisdiction might require D. For the duration of the data subject’s relationship with the organization
- A company’s retention schedule says a class of e-mails is destroyed at the end of each quarter. In month two, the legal department is served with a lawsuit that could involve those e-mails. What must the company do?
A. Destroy the e-mails on schedule, since the schedule was approved by management B. Suspend destruction of the relevant e-mails until the matter resolves or counsel lifts the hold C. Destroy everything except the e-mails explicitly named in the complaint D. Continue normal destruction but keep a copy of the schedule as evidence of good faith
- Under HIPAA’s documentation requirements (45 CFR 164.316(b)(2)), how long must a covered entity retain the documentation of its policies and procedures and its security actions?
A. Three years from the date of creation B. Five years from the date of creation C. Six years from the date of creation or the date it was last in effect D. For as long as the covered entity operates
- Under PCI DSS v4.0, how long must audit log history be retained?
A. At least 12 months, with the most recent 3 months immediately available for analysis B. At least 7 years, matching tax record requirements C. At least 3 years, with the most recent year immediately available D. Until the next PCI DSS assessment is completed
- Under SEC Rule 210.2-06, issued under the Sarbanes-Oxley Act, how long must public-company audit work papers be retained?
A. Three years after the audit report is signed B. Five years after the audit report is signed C. Seven years after the conclusion of the audit D. For the life of the company
- NIST SP 800-88 Rev. 1 defines sanitization as a process to render access to target data on the media infeasible for a given level of effort, and it organizes methods into three categories. Which list is correct?
A. Clear, purge, destroy B. Delete, degauss, destroy C. Overwrite, encrypt, incinerate D. Clear, archive, dispose
- An organization is reusing a moderate-impact hard drive inside the company, moving it to a department that handles only public information. NIST SP 800-88 Rev. 1 asks for which sanitization category?
A. Clear, because the drive stays within the organization and the threat is simple, non-invasive recovery B. Purge, because the drive was ever used for sensitive data C. Destroy, because any reuse of a drive is risky D. No sanitization, because the data was deleted with the operating system
- A team proposes degaussing a solid-state drive before returning it to the lessor. What is wrong with this plan?
A. Degaussing works on SSDs but only erases user data, leaving firmware intact B. Degaussing works only on magnetic media; an SSD stores data as electrical charge in flash cells and will not be affected C. Degaussing is too slow to be practical for a single drive D. Nothing, degaussing is the standard method for all drive types
- Why is overwriting with binary zeros not a reliable way to clear a solid-state drive?
A. SSDs do not support write commands B. Wear leveling, garbage collection, and over-provisioning mean the operating system cannot address every cell that holds data C. SSD firmware rejects all overwrite patterns except the vendor’s proprietary ones D. Overwriting voids the drive warranty, which is not the reason given
- A backup tape holding high-impact data is scheduled for disposal. Which statement about degaussing this tape is correct?
A. Degaussing is appropriate for magnetic tape, and it renders the tape unusable as well as unreadable B. Degaussing is appropriate, and the tape can be reused afterward for lower-classification data C. Degaussing does not work on tape because tapes are optical D. Degaussing is not necessary because tape data is encrypted by default
- A security team plans to dispose of encrypted laptops by crypto erase: delete the local encryption key and resell the laptops. The laptops were encrypted with a FIPS-validated module, and the recovery keys are stored in the company’s escrow service so help desk staff can unlock them. What is the flaw?
A. FIPS-validated modules cannot be crypto-erased B. The escrowed recovery key copies survive the local deletion, so the data is still recoverable C. Reselling laptops is prohibited regardless of sanitization D. Crypto erase works only on HDDs, not SSDs
- A cloud team deletes the current version of an object containing customer data from an object store. Under what circumstances can the data still exist after this action?
A. Only if the provider’s storage is defective B. If previous object versions, snapshots, automated backups, or cross-region replicas exist, the data can survive in them C. The data is gone once the object pointer is removed D. The data survives only if the bucket is publicly readable
- In a cloud deployment, who is responsible for physically destroying the storage media that holds a customer’s data at the end of its service life?
A. The customer, using its own degaussing equipment B. The provider, through its media decommissioning process, evidenced by its compliance attestations and contract terms C. No one, because cloud media is never destroyed D. The customer and provider jointly, on the customer’s premises
- A company discards boxes of paper files that contain consumer report information. Under the FTC Disposal Rule (16 CFR Part 682), what does the law require?
A. The files must be kept indefinitely B. Reasonable measures to protect against unauthorized access to the information in and after disposal, such as cross-cut shredding or incineration C. The files may be recycled whole because paper is not an information medium D. A written waiver from each consumer before disposal
- A company contracts a third-party vendor to destroy old drives and tapes. What makes the disposal defensible in an audit?
A. A verbal agreement with the vendor B. Due diligence on the vendor, a contract stating the sanitization requirements, and a certificate of destruction listing the serial numbers and method C. The vendor’s promise to recycle all media D. Nothing, because outsourced destruction is always the customer’s only liability
- A user “deletes” a file from a laptop’s hard drive and the recycle bin is emptied. Which statement about the file’s data is correct?
A. The data is gone because the directory entry was removed B. The bytes can remain in unallocated space or slack space, recoverable with file-recovery tools C. The data is gone only if the laptop is restarted afterward D. The data is gone because the operating system overwrites deleted files immediately
- NIST SP 800-88 Rev. 1 bases the sanitization decision on which two variables?
A. The age of the media and the brand of the drive B. The confidentiality of the information and the type of media C. The size of the data and the number of users D. The cost of the media and the resale value
Answers and rationales
-
B. Retention is governed by the longest applicable legal or regulatory minimum, here the tax authority’s seven years, and the reasonably anticipated litigation acts as a hold that suspends destruction of relevant records. Business need (option A and C) cannot shorten a legal floor, and choosing the shortest period (option D) violates the regulatory requirements.
-
B. Article 5(1)(e) sets the storage limitation: personal data may be kept in identifiable form only as long as is necessary for the purposes of the processing. Storage capacity (option A), speculative foreign laws (option C), and relationship duration (option D) are not the standard; the test is necessity tied to purpose.
-
B. Once litigation is reasonably anticipated, the duty to preserve suspends scheduled destruction of relevant records. The approved schedule does not override the hold (option A), destruction cannot continue selectively around the complaint (option C), and keeping only a schedule copy does not cure the destruction of the records themselves (option D). Destroying held records is spoliation.
-
C. 45 CFR 164.316(b)(2), the Security Rule’s documentation provision, requires retention for six years from the date of creation or the date the documentation was last in effect, whichever is later, and the Privacy Rule carries the same six-year period at 45 CFR 164.530(j). Three years, five years, and lifetime (options A, B, and D) are not the regulatory periods.
-
A. PCI DSS v4.0 Requirement 10.5.1 requires retaining audit log history for at least 12 months, with at least the most recent 3 months immediately available for analysis. Seven years (option B) belongs to audit work papers under the SEC rules, three years (option C) matches no PCI requirement, and the assessment cycle (option D) is unrelated to log retention.
-
C. SEC Rule 210.2-06 requires retention of audit documentation for seven years after the conclusion of the audit. Three and five years (options A and B) are not the rule, and company lifetime (option D) is not required.
-
A. NIST SP 800-88 Rev. 1 organizes sanitization into clear, purge, and destroy. Delete, degauss, encrypt, incinerate, archive, and dispose (options B, C, and D) are techniques and lifecycle words, not the standard’s three categories.
-
A. Clear is the category for media staying within the organization and being reused, because clearing prevents simple, non-invasive recovery, which is the threat for an internal reuse. Purge (option B) is the bar for media leaving organizational control, destroy (option C) is for end-of-life or highest-impact data, and skipping sanitization (option D) ignores that deleting files leaves recoverable bytes.
-
B. Degaussing acts on magnetic domains and works only on magnetic media. SSDs store charge in flash cells and are unaffected by magnetic fields, so the drive would leave the organization with its data intact. Options A, C, and D misstate the method’s mechanism or effect.
-
B. Wear leveling, background garbage collection, and over-provisioned spare cells mean the operating system cannot address every cell holding data, so an overwrite pass cannot reach all of it. SSDs support writes (option A), the mechanism is firmware behavior rather than a policy of rejecting patterns (option C), and warranty concerns are irrelevant (option D).
-
A. Degaussing works on magnetic tape, and because it randomizes the magnetic domains including any servo structure, the tape is unusable for storage afterward. It cannot be reused for lower-classification data (option B), tapes are magnetic rather than optical (option C), and tape encryption is a separate control that does not obviate disposal (option D).
-
B. Crypto erase is valid only when the key material is truly gone. The escrow copies held for help desk recovery survive the laptop’s local key deletion, so the data remains recoverable. FIPS validation is a precondition, not a disqualifier (option A), laptop resale is permitted with proper sanitization (option C), and crypto erase applies to SSDs as much as HDDs when properly implemented (option D).
-
B. Cloud data multiplies into object versions, snapshots, automated backups, and cross-region replicas, and deleting the current version’s pointer leaves those copies untouched. The failure is the inventory gap, not defective storage (option A), and public readability (option D) has nothing to do with whether the copies exist.
-
B. Physical destruction of underlying media belongs to the provider’s decommissioning process, and the customer verifies it through compliance attestations and the contract terms. The customer cannot access or degauss provider media (option A), cloud media is destroyed on provider cycles rather than never (option C), and the destruction happens on provider facilities under provider process (option D).
-
B. The FTC Disposal Rule requires reasonable measures to protect against unauthorized access to consumer report information in and after disposal; cross-cut shredding and incineration are the classic compliant methods for paper. Indefinite retention (option A), whole recycling (option C), and individual waivers (option D) are not the rule’s terms.
-
B. Outsourced destruction is defensible when the organization does due diligence on the vendor, contracts the sanitization requirements, and receives a certificate of destruction with serial numbers, dates, and methods. A verbal arrangement (option A), recycling promises (option C), and the claim that nothing is defensible (option D) all fail the documentation standard.
-
B. Deleting a file removes the directory entry and marks space as available; the bytes remain in unallocated space or slack space until overwritten, recoverable with file-recovery tools. Options A, C, and D all assume the deletion removed the data, which is precisely the remanence error this chapter exists to correct.
-
B. NIST SP 800-88 Rev. 1 drives the decision from the confidentiality of the information and the media type. Age, brand, size, user count, cost, and resale value (options A, C, and D) do not determine the sanitization category; classification and medium do.
Retention, handling, and disposal on one page
The lifecycle has three decisions and one paper trail. Retention answers how long: the schedule sets a period that clears the longest applicable legal and regulatory floor, honors the documented business need, and respects the minimization ceiling of laws like the GDPR’s Article 5(1)(e) storage limitation, with a litigation hold as the master switch that suspends destruction the moment legal matters are reasonably anticipated. The numbers to carry are the ones this chapter named: seven years for SOX audit work papers under SEC Rule 210.2-06, six years for HIPAA documentation under 45 CFR 164.316(b)(2), twelve months of audit logs with three immediately available under PCI DSS v4.0 Requirement 10.5.1. Handling answers how safely: marking, inventory, access, encrypted transport, and environmental protection, governed by ISO/IEC 27001:2022 control 7.10 and the NIST SP 800-53 media protection family. Disposal answers how completely: NIST SP 800-88 Rev. 1’s ladder of clear, purge, and destroy, selected by confidentiality impact and media type, with overwrite for HDDs, secure erase or destruction for SSDs, degaussing for magnetic media only, destruction for optical and paper, and crypto erase only when the encryption was validated, complete, and its key copies are truly gone. The cloud changes the tools, not the logic: the customer deletes logically, destroys keys, and verifies, while the provider destroys media and evidences it through attestations and the Article 28 data processing agreement. Every step ends in a record, the sanitization log, the certificate of destruction, the deletion confirmation, the sign-off, because in retention, handling, and disposal, the document is the control.
Chapter 11 is the Domain 2 practice test, twenty-five questions that will ask you to make these calls under time pressure. Before you go, hold the one sentence that anchors the whole domain: an asset is not disposed of when someone says it is deleted; it is disposed of when the data is unrecoverable at the level of effort the classification demands, and someone has written that down.
Continue reading
Full table of contents