Home > Ask the Security Experts > Platform Security Questions & Answers > The pros and cons of data wiping
Ask The Security Expert: Questions & Answers
EMAIL THIS

The pros and cons of data wiping

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 08 August 2006
We are currently using a well known "wipe" utility, but it is taking eight hours to make one pass. Typical security has called for a minimum of three and up to seven passes to "ensure" that everything is completely gone. Is there a secure wipe utility that can help us safeguard our data in less than eight hours?

>
EXPERT RESPONSE
Performing a wipe is a time-consuming process and is exacerbated by the fact that relative to their capacity modern hard drives are slow. Most wipe tools reach the disk's physical limits because the CPU, memory and IDE, SCSI and SATA drives. If your wipe times don't improve, it may be because DBAN doesn't have a specific driver for your motherboard chipset, however you can contact them if this is the case.

Also review the number of passes that you really require to safeguard your data. If you need to guarantee that your data is wiped, then a wipe done to the U.S. Department of Defense's DoD 5220.22-M (8-306. /E) standard will over-wipe all addressable hard drive locations with a character, its complement and a random character followed by verification. This process is completed three times and prevents data from being recovered by commercially available processes. DoD 5220.22-M (8-306. /E, C & E) is a seven-pass wipe and is only required for the most sensitive of information. However, in the fall of 2004, the U.S. National Security Agency (NSA Advisory LAA-006-2004) found that a single overwrite using DoD 5220.22-M compliant software is sufficient to render electronic files unrecoverable.

Unfortunately software disk-wiping cannot sanitize disconnected, forgotten internal hard drives, or hard drives that have physically failed. Therefore, if you don't need your drives again consider destroying them by degaussing, melting, incineration, crushing or shredding. Also know that with both methods, software-wiping or physical destruction, you'll need to implement policies and procedures that govern hard drive disposal. You must also train employees to ensure that you have taken "reasonable measures" to safeguard your data. The FTC's FACTA rule on the proper storage and disposal of certain consumer information requires any business that maintains or otherwise possesses consumer information, or any compilation of consumer information, derived from consumer reports for a business purpose, to properly dispose of such information or compilation. Although physically destroying disks is more costly than wiping them, the potential costs associated with compromised data may make it the best option.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Platform Security
How can 'DRAM remanence' compromise encryption keys?
Should users have a removable boot drive for online banking?
The unexpected costs of server virtualization?
Is attack code valuable for vulnerabilities or just a publicity stunt?
Will the features of Windows Vista SP1 encourage wider adoption of the OS?
Is a Master Boot Record (MBR) rootkit completely invisible to the OS?
What are the pros and cons of zero-knowledge penetration tests?
Are open recursive DNS servers inherently insecure?
Should whole disk encryption products be used with data backup software?
Which operating system can best secure an FTP site?

Data Backup
Should users have a removable boot drive for online banking?
Should whole disk encryption products be used with data backup software?
Will one failed drive corrupt the rest of a RAID-5 array?
The Craft of System Security
Can confidential data be accessed once it is deleted for free space?
Examining DoD-level secure erasure guidelines
What is the relationship between open port range and overall security risk?
Compliance, data breaches heighten database security needs
Are encryption products better than self-destructing data?
What is a logic bomb?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
Targeted Security Channel Tips for Resellers, Integrators and Consultants
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts