Ninety-five million dollars in penalties, a moving company that shouldn't have been there, and the standard that quietly changed in September 2025.
NIST SP 800-88 Revision 1 (2014) was withdrawn and superseded in September 2025. A great deal of the ITAD guidance still circulating online cites the withdrawn version.
The complete transcript — 3,006 words. Search it, quote it, or send the relevant section to a colleague who needs to see it.
Hey everybody, and welcome back to the Operational ITAM Podcast. I'm Bill Van Nort, and today we are going all the way to the end of the line. Back in episode one, I promised you an episode about disposal and data destruction, featuring some genuinely alarming stories about hard drives turning up where they should not be. I said flea markets.
I was wrong. The real story is worse. It was an internet auction. It involved 15 million people, and it cost one company $95 million in regulatory penalties. We'll get to that. Good morning, good afternoon, or good evening, wherever you're listening from. This is the show where we take the unglamorous machinery of enterprise technology and make it make sense.
Grab your coffee. This one has teeth. Here's the premise for today. Everything we've covered so far has been about assets, things you own, things you control, things that produce value. Disposal is the moment that stops being true. At the end of life, a device stops being an asset and becomes something else entirely. It becomes a liability with a serial number.
And unlike every other gate in the lifecycle, this is the one where getting it wrong doesn't cost you efficiency or budget. It costs you a regulator. So let's do this properly. What the standard actually says now, and it changed recently. What the regulations actually require. What the certifications actually verify? And what happens when a very large, very sophisticated organization gets it wrong?
Let's start with the standard, because there is a good chance yours is out of date. If your organization has a data destruction policy, and if it doesn't, we have a bigger conversation, it almost certainly cites NIST Special Publication 800-88. That document has been the reference for media sanitization since 2006. When an auditor asks how you destroyed data, sanitized in accordance with NIST 800-88 is the answer they're looking for.
Here's what most people don't know. On September 26, 2025, NIST published Revision 2, and on the same day, they withdrew Revision 1 entirely. Not deprecated, not superseded going forward, withdrawn, and archived with a warning notice on the front page, provided solely for historical purposes. Revision 1 had been the standard for 11 years.
An enormous amount of policy language, contract language, and vendor marketing was written against it. Much of that material is still circulating, still being cited, and still being handed to auditors. And it now points at a withdrawn document. So what actually changed? The three methods survived. Clear, purge, and destroy. Clear protects against simple recovery.
Purge defeats laboratory recovery. Destroy renders the media physically unusable. Those definitions are intact. What changed is everything around them. Revision 1 was a technical manual. It told you, device by device, media type by media type, which technique to apply. It had tables. People loved those tables. Revision 2 removed them. In NIST's own words, apart from cryptographic erase, all sanitization techniques and tool details have been replaced with recommendations to comply with IEEE 2883 NSA specifications or an organizationally approved standard.
Think about what that means. NIST looked at a decade of storage technology moving faster than a publication cycle and concluded that a static table is obsolete the moment it's printed. So they got out of that business and pointed at a standard that gets maintained. The second change is bigger, and it's the one that matters for how you run a program.
The focus shifted from hands-on sanitization decisions to establishing an enterprise media sanitization program. It's now aligned with the broader cybersecurity control families SP 800-53, ISO 27040. It is a governance document now, not a how-to guide. And third, this is the one I want you to sit with. Revision 2 elevates verification and it explicitly addresses trust establishment in the vendor's implementation of sanitization techniques.
Read that again. NIST added language about whether you can trust that your vendor actually did what they said they did. That is not a technical concern, that is a supply chain concern, and it exists in the document because the failure mode is real. Let me say the practical version. Under revision 2, a sanitization operation you did not verify is not a completed sanitization operation, it's an assertion.
Two quick corrections while we're here, because both of these are still circulating and both are wrong. Degaussing. It is no longer an approved destroy technique under the current guidance for modern media. If your policy says degauss, your policy is describing a magnetic era that your storage estate has largely left behind. A degausser does nothing meaningful to a solid state drive.
And the big one, multi-pass overwriting. Three passes, seven passes, 35 passes. That lineage traces back to an old Department of Defense manual, and it has been folklore for years. For flash media, it is worse than folklore, because wear leveling means the controller decides where writes land, and you cannot guarantee you touched every cell.
The modern answer for encrypted media is cryptographic erase. Destroy the key and the data is mathematically unreachable, regardless of what cells it occupies. It is faster, it is more reliable, and it is the one technique NIST kept detailed guidance on. If your policy still says 7 passes, you are spending time on a ritual.
All right, and now, the $95 million story I promised you. What the regulations actually require, and why there isn't just one. And how to read a certificate of destruction, which is a document that is very often worth exactly nothing. You're listening to the Operational ITAM Podcast. I'm Bill. Before the story, a listener question. And this one is so common, I want to answer it properly.
Marcus in Fort Wayne writes, Bill, we wipe every drive in-house before it goes to our ITAD vendor, and then they wipe it again and give us a certificate. My boss says we're doing the same work twice and wants to stop the in-house step. Is he right? Marcus, your boss is asking a reasonable question, and I'm going to disagree with him anyway.
Here's the thing. That in-house wipe is not duplicated effort. It's the only sanitization step that happens while the device is still under your control. Think about what you're actually buying with it. Between your loading dock and your vendor's shredder, there is a truck, a driver, a warehouse, a queue, and possibly a subcontractor. That window is the single highest risk period in the entire life of that asset, and it's the one period where you have the least visibility.
If the drive leaves your building already sanitized, that window stops being a data risk. It becomes a logistics risk. Those are very different problems, and the second one is far cheaper when it goes wrong. Now, the honest caveat. Your in-house wipe has to be verified, or you've just given yourself a false sense of security, which is worse than none.
Revision 2 is explicit on that point. Log it, verify it, and keep the record. So no, don't stop. And here's how I'd frame it for your boss. We are not wiping twice. We are removing the data before it leaves our custody, and then paying somebody to prove it's gone. Those are two different controls, and only one of them is in our hands. Belt and braces.
Every time. All right, now the story. Between 2015 and roughly 2020, Morgan Stanley, a firm with resources with a compliance function, with everything you would assume protects against this, decommissioned two data centers and later refreshed servers across local offices and branches. For the data center work, they engaged a moving and storage company, not an ITAD provider.
A moving and storage company, which the Securities and Exchange Commission would later describe as having no experience or expertise in data destruction services. Roughly 4,900 devices moved through that engagement. The moving company sold devices to a third party. That third party put them on an internet auction site, and some of those devices still had unencrypted customer information on them.
Morgan Stanley recovered some. Not, in the SEC's words, the vast majority. Then there's the second failure, which I find even more instructive. During a separate hardware refresh, roughly 500 servers were replaced across offices and branches. 42 of them were never accounted for, just gone from the record. And those servers had encryption capability.
The firm had simply never turned it on. When they eventually did, a manufacturer flaw meant it only encrypted newly created data. So the historical information sitting on those drives stayed in the clear. The numbers. The Office of the Comptroller of the Currency fined them $60 million in October 2020. The SEC added $35 million in September 2022. $95 million across two regulators for asset disposition.
15 million customers affected. The SEC's enforcement director called the failures astonishing. Now, why do I tell you this story rather than one of mine? Because it's public record, every detail of it is documented in enforcement orders you can read yourself. And because I want you to notice something specific about it, nobody at Morgan Stanley decided to leak customer data.
There was no breach in the way we normally use that word. No attacker, no exploit, no ransomware. What happened is that a hardware refresh, an operational, unglamorous IT asset management activity, was handed to a vendor nobody qualified, without oversight, without verification, and without anyone tracking whether the devices arrived where they were supposed to.
Every single control that failed there is an asset management control. That's the episode. That's why disposal isn't a footnote on the life cycle.
Let's talk about the regulations, because here's the thing that surprises people. There is no single disposal rule. The Gramm-Leach-Bliley Act Safeguards Rule requires financial institutions to maintain a written information security program covering secure disposal of customer information. And note, the FTC's definition of financial institution is far broader than banks.
It reaches insurance, mortgage brokers, tax preparers, debt collectors, auto dealers offering financing. The amendments that took effect in June 2023 made disposal explicit and added a third-party service provider oversight requirement, which, if you're keeping score, is precisely the control Morgan Stanley didn't have. The FACTA Disposal Rule requires reasonable measures for disposing of consumer report information.
That's the Fair and Accurate Credit Transactions Act, and it applies to anyone who uses a consumer report, including for employment background checks, which is most of you. HIPAA's Security Rule requires covered entities and business associates to render electronic protected health information unreadable and unrecoverable before disposal.
PCI DSS version 4 requires that media containing cardholder data be destroyed or rendered unrecoverable. It's the most prescriptive of the group. For high-sensitivity media, software wiping alone is generally not considered sufficient. Sarbanes-Oxley governs retention of financial records. Regulation S-P is what caught Morgan Stanley. And then there's a patchwork of state law on top of all of it.
Here's the practical implication, and it's simpler than the list suggests. A single laptop from a finance department might hold customer financial information, consumer report data, records under a retention obligation, and personal information belonging to residents of states with their own statutes. One device. Four or five frameworks.
You do not build four disposal processes. You build one, documented to the strictest applicable standard. and it satisfies the others. And every one of those frameworks wants the same two things from you. Evidence that the data was destroyed, and records proving it. Retention periods vary. Six years under HIPAA, seven for audit records under Sarbanes-Oxley.
When several apply, keep the records for the longest one. Now, vendors and certifications, because this is where people get a false sense of security. Three certifications matter, and they do not verify the same things. R2v3, administered by SERI, is the responsible recycling standard. It grew out of a process the EPA convened back in 2006.
Its most valuable feature for you is downstream due diligence. A certified facility has to document every vendor its materials pass through after leaving the building. Not claim it, chart it. e-Stewards, administered by the Basel Action Network, is stricter. It requires NAID AAA certification as a precondition. It requires an environmental management system.
It applies to every facility a company operates rather than allowing selective certification. It bans export of electronics to developing countries. And certified organizations submit to unannounced inspections and GPS tracking audits. NAID AAA, administered by i-SIGMA, is the one that's specifically about data destruction. Every requirement in it addresses information security, destruction methods, facility security, employee vetting, documentation, chain of custody.
And its distinguishing feature is unannounced audits. Here's the combination to remember. An environmental certification plus a data destruction certification. R2v3 plus NAID AAA is the practical floor for anyone handling regulated data. e-Stewards, if your organization has real ESG commitments, or international exposure. But I want to flag the gap that auditors find over and over.
Your vendor certification covers your vendor's facility. If they subcontract destruction to a third party, that certification does not automatically extend to the subcontractor. Breaches in this space tend to happen downstream, not at the primary facility. So the question is not, are you certified? The question is, show me your downstream chain and show me the certifications at each link.
Which brings us to the document at the center of all of this. The certificate of destruction. I have seen a lot of these, and a great many of them are worthless. Here is what a worthless one looks like. One pallet of mixed electronics was destroyed on this date. Signature. Logo. Very official looking. That document proves nothing. It doesn't tell you which devices.
It doesn't tie to your records. And in an audit, it will not survive the first follow-up question. A defensible certificate of destruction is serialized. Every device listed individually. Make. Model. Serial number. The sanitization method applied to each. The date. the operator. And it reconciles against your own asset records, so you can demonstrate that the device you retired is the device that was destroyed.
If you cannot draw a line from your asset register to a serial number on a destruction certificate, you do not have a chain of custody. You have two unrelated documents that happen to be in the same folder.
Alright, let's take it to the library one more time because this is the last room in the building and it's the one nobody wants to walk into. Every library has a back room. It's where the withdrawn books go. The water-damaged, the superseded, the ones that finally fell apart. And the head librarian will tell you that deaccession is the most procedurally strict thing the institution does, stricter than acquisition, because a book that leaves the collection improperly can never be recalled.
So there's a ledger. Every withdrawn item listed by catalog number. Not a cart of old books. Each one. Who authorized it, what happened to it, and on what date. The shredder is in the back with a log, a certificate, and a clean conscience. We said that in Volume 2. Today I'll tell you what makes the conscience clean. It is not the shredder.
Anybody can own a shredder. It's the ledger. And if you hand your withdrawal cart to a contractor at the loading dock without writing down what was on it, then whatever happens next is still your name on the catalog card. The library's reputation does not transfer with the cart. One closing principle, and the arc continues. Hardware is a custody discipline.
Software is an evidence discipline. Audit defense is a process discipline. Settlement is a commercial discipline. Shadow IT is a service discipline. Refresh is an economic discipline. Disposal? Disposal is a liability discipline. Everywhere else in the lifecycle, doing this badly costs you money or efficiency. Here, doing it badly transfers your data to somebody else while leaving the accountability with you.
That is the only gate where the downside isn't a number on a budget. It's a consent order with your company's name on it, $95 million. From a moving company, and 42 servers nobody wrote down. Class dismissed. Here's your homework, and this one takes about an hour. Go and get your three most recent certificates of destruction, any three. Now open your asset register.
For each certificate, pick one serial number and find it in your records. Then go the other direction. Pick a device your records say was disposed of and find it on a certificate. That's it. Both directions. Six lookups. If every one reconciles, you have a chain of custody and you should be quietly proud, because most organizations do not.
If your certificates say mixed electronics and don't list serial numbers at all, you've just learned something important and you learned it on a Tuesday instead of during an incident. And while you have the certificates out, check one more thing. What standard do they cite? If it says NIST 800-88 Revision 1, your vendor is certifying to a document that was withdrawn in September of 2025.
That is a conversation worth having at your next review. Next episode, we're going somewhere much more optimistic. Renewals. The one moment in the entire vendor relationship where you hold the leverage, and almost nobody uses it because they start the conversation 60 days out instead of 18 months out. If you've ever opened a renewal quote and felt your stomach drop, that one's for you.
And listen, I promised you listener case files back in episode one, and I meant it. If you've got a situation you'd like me to work on air, anonymized, sanitized, no company names, send it over at operationalitam.com. Real constraints, real politics, real budgets. I'm Bill Van Nort. This is the Operational ITAM podcast. Serialize the certificate, verify the destruction, keep the ledger, and I'll see you at the negotiating table next week.
Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. Situations get worked on air.