
Solution 04 / Secure Data Destruction
Media sanitization and destruction with documented chain of custody.
Define the controlled media population, authorized custody points, client-approved sanitization or destruction method, verification and validation requirements, exception process, and final documentation before devices leave the site.
Follow the custody spine →- Scope
- Policy
- Capture
- Control
- Method
- Evidence
Chain of custody / working structure
Define custody and processing records before media starts moving.
The sequence creates control points; it does not imply one method for every device. Client policy and media characteristics determine the approved sanitization or destruction direction.
- 01Scope
Define the media population.
Identify device and media types, locations, ownership, quantities or references, embedded storage, exclusions, unknowns, and which assets may remain eligible for reuse.
- 02Policy
Translate the client decision into the work plan.
Document the client’s data sensitivity, reuse decision, approved handling direction, on-site or off-site constraints, authorization, evidence needs, and exception path.
- 03Capture
Create the required identifier relationship.
Agree whether evidence is organized by asset, media item, container, batch, or another project-specific reference before custody events begin.
- 04Control
Define each transfer and protected state.
Specify who can handle the media, secure containers or areas, seals if applicable, scan or count points, transport interfaces, destination, and escalation conditions.
- 05Method
Apply the approved media-specific direction.
The selected method depends on media characteristics, sensitivity, reuse intention, client policy, available capability, verification needs, and the approved project scope.
- 06Evidence
Resolve results and exceptions into closeout.
Connect identifiers or groups to custody events, method records, incomplete results, missing items, substitutions, approvals, and the final material agreed for stakeholder review.
Decision table / media-specific review
Method follows media type, sensitivity, reuse intent, and client policy.
NIST SP 800-88 Rev. 2 informs the Clear, Purge, and Destroy terminology used here. The applicable method, provider, and records remain project-specific.
| Media context | Sensitivity | Reuse decision | Method review |
|---|---|---|---|
| Magnetic storage | Client-defined | Possible or no | Select an approved clear, purge, or destroy approach only after media and policy review. |
| Solid-state storage | Client-defined | Possible or no | Account for flash behavior, device capability, verification, and whether physical destruction is required. |
| Mobile / embedded | Client-defined | Device-dependent | Confirm embedded media, management locks, reset capability, access, and the evidence the project needs. |
| Damaged or inaccessible | Client-defined | Usually constrained | Use an approved exception path when normal processing, identification, or verification cannot be completed. |
| Mixed or unknown | Unresolved | Unresolved | Hold separately, identify the media, and obtain a route decision rather than applying a default label. |
Processing documentation
Build final documentation from the complete processing record.
Follow the authorized media population through custody, processing results, exceptions, and stakeholder review.
- 01
Identity & custody
Connect each asset, media item, container, or batch to its required custody checkpoints.
- 02
Method & exceptions
Record the approved direction, result, failed processing, missing items, and identifier conflicts.
- 03
Final documentation
Assemble the agreed summaries, processing records, and exception notes for stakeholder review.
Contact TALC
Need a media handling plan?
Send the media types, estimated quantity, reuse intent, and onsite or offsite requirement.
Contact TALC