Technical Guide

NIST SP 800-88 International Data Erasure Standards Explained - 3 Erasure Levels Enterprises Should Know

Detailed explanation of NIST SP 800-88 data erasure guidelines established by the US National Institute of Standards and Technology. Learn about Clear, Purge, and Destroy erasure levels and application scenarios.

NIST SP 800-88 International Data Erasure Standards

What are International Data Erasure Standards?

International standards exist for data erasure. The most prominent is NIST SP 800-88.

What is NIST SP 800-88?

Media Sanitization Guidelines established by the US National Institute of Standards and Technology (NIST)

  • Official Name: NIST Special Publication 800-88 Revision 1
  • Publication Year: 2014
  • Scope: HDDs, SSDs, optical media, mobile devices, etc.

Three Erasure Levels

Level 1: Clear

Definition:

Data erasure through logical overwriting

Methods:

  • Software-based full area overwriting
  • One or more random data writes
  • File system level erasure

Application Scenarios:

  • Internal reuse
  • Low-sensitivity data
  • Regular business data
MASAMUNE Support: ✅ Supported

Level 2: Purge

Definition:

Complete data erasure at physical level

Methods:

  • Multiple overwrites (DoD 5220.22-M, etc.)
  • Secure Erase (SSD-specific commands)
  • Cryptographic erasure

Application Scenarios:

  • External transfer/sale
  • Data containing personal information
  • Trade secret level data
MASAMUNE Support: ✅ Supported

Level 3: Destroy

Definition:

Complete prevention of data recovery through physical destruction

Methods:

  • Physical shredding
  • Melting
  • Incineration
  • Degaussing (HDDs)

Application Scenarios:

  • National security level
  • Financial institution critical data
  • When not reusing
MASAMUNE Support: Partial (erasure only, physical destruction separate)

Other International Standards

ISO/IEC 27040

  • Storage security in information security management
  • Consistent with NIST SP 800-88

ADISA

(Asset Disposal and Information Security Alliance)

  • Data erasure product certification body
  • Globally recognized certification

UK HMG Infosec Standard 5

  • UK government standards
  • Specifies erasure methods by classification level

Erasure Levels Enterprises Should Choose

Data SensitivityRecommended LevelErasure Method
General business dataClearSingle overwrite
Personal informationPurge3+ overwrites
Trade secretsPurgeSecure Erase
National secretsDestroyPhysical destruction

MASAMUNE Erasure Compliance

Compliant Standards

  • NIST SP 800-88 compliant
  • DoD 5220.22-M compatible
  • ISO/IEC 27040 consistent

Provided Erasure Levels

  • Clear: Single overwrite (high-speed processing)
  • Purge: Triple overwrite (standard)
  • Purge+: Secure Erase (SSD)

Certificate Issuance

  • International standard compliance noted
  • Erasure algorithm documentation
  • Detailed logs for audit compliance

Summary

International standard-compliant data erasure is essential for corporate compliance. Understand NIST SP 800-88 and select appropriate erasure levels.

Talk with Us