A healthcare organization is preparing to decommission an array of enterprise Self-Encrypting Drives (SEDs) containing magnetic platters that stored protected health information (PHI). The IT department plans to reassign these physical hard drives to a non-sensitive internal development environment. The compliance policy requires a NIST-compliant purge method that renders all historical data unrecoverable via advanced laboratory techniques while preserving the drive hardware for immediate reuse. Which of the following data disposition methods should the technician perform?
- Perform a Cryptographic Erase (CE) to destroy the internal media encryption keys.Answer
- BExpose the magnetic drives to a high-coercivity degaussing coil.
- CRun an industrial physical disk shredder to reduce the drives to small particles.
- DExecute a full format on each drive using the operating system disk management console.
Answer
Performing a Cryptographic Erase (CE) to destroy the internal media encryption keys.
Performing a Cryptographic Erase (CE) on Self-Encrypting Drives (SEDs) permanently erases or overwrites the symmetric media encryption key stored in the controller onboard memory. Without the key, existing encrypted data on the platters becomes unreadable ciphertext that cannot be decrypted even with specialized laboratory recovery techniques. Because the physical magnetic structure of the disk is unaltered, the drive can be re-initialized with a new key and safely redeployed.
Step-by-Step Solution
Key Concept
Data Sanitization Standards (NIST SP 800-88) and Cryptographic Erase
Estimated Time:2m 0s