1
00:00:00,000 --> 00:00:01,740
In this lesson, we're going to talk about

2
00:00:01,740 --> 00:00:04,110
asset disposal and decommissioning.

3
00:00:04,110 --> 00:00:05,790
Now an organization is going to expand

4
00:00:05,790 --> 00:00:08,130
and modernize its technology stack over time

5
00:00:08,130 --> 00:00:09,960
and there's going to be a significant volume of data,

6
00:00:09,960 --> 00:00:12,510
software, hardware and services that are accumulated,

7
00:00:12,510 --> 00:00:14,010
and eventually they're going to outlive

8
00:00:14,010 --> 00:00:15,810
their usefulness and purpose.

9
00:00:15,810 --> 00:00:17,790
However, we can't simply throw away these assets

10
00:00:17,790 --> 00:00:18,690
in the trash.

11
00:00:18,690 --> 00:00:21,060
Instead, we need to have a proper procedure in place

12
00:00:21,060 --> 00:00:23,370
to ensure the data security, regulatory compliance,

13
00:00:23,370 --> 00:00:25,950
and efficient use of resources is occurring.

14
00:00:25,950 --> 00:00:26,970
To help us with this,

15
00:00:26,970 --> 00:00:29,130
the National Institute of Standards and Technology

16
00:00:29,130 --> 00:00:32,940
created a document known as the Special Publication 800-88

17
00:00:32,940 --> 00:00:34,080
which is commonly referred to

18
00:00:34,080 --> 00:00:36,840
as the Guidelines for Media Sanitization.

19
00:00:36,840 --> 00:00:39,060
Now, these guidelines provide our organizations

20
00:00:39,060 --> 00:00:41,220
with guidance on how to conduct sanitization,

21
00:00:41,220 --> 00:00:44,130
destruction and certification for our asset disposal

22
00:00:44,130 --> 00:00:46,080
and decommissioning processes.

23
00:00:46,080 --> 00:00:48,150
Now, first we have sanitization.

24
00:00:48,150 --> 00:00:50,490
Sanitization refers to the thorough process

25
00:00:50,490 --> 00:00:53,070
of making data inaccessible and irretrievable

26
00:00:53,070 --> 00:00:56,370
from a storage medium using traditional forensic techniques.

27
00:00:56,370 --> 00:00:58,350
Now, whether the data is stored on a hard drive,

28
00:00:58,350 --> 00:01:00,060
solid state device, memory card,

29
00:01:00,060 --> 00:01:01,680
or other type of storage device,

30
00:01:01,680 --> 00:01:03,390
sanitization is going to be used to ensure

31
00:01:03,390 --> 00:01:04,769
that it completely is removed

32
00:01:04,769 --> 00:01:06,720
so that it is impervious to recovery,

33
00:01:06,720 --> 00:01:09,090
even with some advanced forensic techniques.

34
00:01:09,090 --> 00:01:11,100
Common methods employed in sanitization

35
00:01:11,100 --> 00:01:13,380
include overriding your data multiple times,

36
00:01:13,380 --> 00:01:14,670
degaussing the storage medium,

37
00:01:14,670 --> 00:01:16,680
or employing encryption techniques.

38
00:01:16,680 --> 00:01:18,630
Our primary objective of sanitization

39
00:01:18,630 --> 00:01:20,010
is to protect sensitive information

40
00:01:20,010 --> 00:01:21,390
from unauthorized access,

41
00:01:21,390 --> 00:01:22,680
especially when disposing of

42
00:01:22,680 --> 00:01:24,960
or repurposing a storage device.

43
00:01:24,960 --> 00:01:27,660
Now, one of our sanitization techniques that we commonly use

44
00:01:27,660 --> 00:01:29,880
is to overwrite data multiple times.

45
00:01:29,880 --> 00:01:32,250
Overwriting data multiple times involves replacing

46
00:01:32,250 --> 00:01:34,020
the existing data on a storage device

47
00:01:34,020 --> 00:01:35,850
with a random series of information

48
00:01:35,850 --> 00:01:38,040
to ensure that the original data is going to be obscured

49
00:01:38,040 --> 00:01:40,770
if anybody tries to recover it using forensic techniques.

50
00:01:40,770 --> 00:01:43,830
Now, this overriding process is often repeated several times

51
00:01:43,830 --> 00:01:46,890
to reduce any chance of the original data being recovered.

52
00:01:46,890 --> 00:01:48,990
Most commonly, overwriting processes

53
00:01:48,990 --> 00:01:52,680
are going to use a single pass, seven passes, or 35 passes,

54
00:01:52,680 --> 00:01:54,600
depending on the classification level of the data

55
00:01:54,600 --> 00:01:55,890
that you're trying to sanitize,

56
00:01:55,890 --> 00:01:58,560
with higher classification levels needing more passes

57
00:01:58,560 --> 00:02:00,600
during that overriding process.

58
00:02:00,600 --> 00:02:03,060
Now, the logic behind this method is that each overwrite

59
00:02:03,060 --> 00:02:05,010
is going to make it increasingly more difficult

60
00:02:05,010 --> 00:02:07,650
for potential adversaries to retrieve any meaningful data

61
00:02:07,650 --> 00:02:09,930
using forensic tools or techniques.

62
00:02:09,930 --> 00:02:12,120
By employing this technique, we're not only ensuring

63
00:02:12,120 --> 00:02:14,040
the confidentiality of our stored data,

64
00:02:14,040 --> 00:02:15,300
we're also minimizing the risks

65
00:02:15,300 --> 00:02:18,060
associated with data breaches or unauthorized access,

66
00:02:18,060 --> 00:02:21,510
especially during device disposal or repurposing.

67
00:02:21,510 --> 00:02:23,370
Now, another sanitization technique we have

68
00:02:23,370 --> 00:02:24,810
is known as degaussing.

69
00:02:24,810 --> 00:02:26,760
Now, degaussing involves using a single machine

70
00:02:26,760 --> 00:02:29,400
called a degausser to produce a strong magnetic field

71
00:02:29,400 --> 00:02:32,310
that can disrupt the magnetic domains on a storage device

72
00:02:32,310 --> 00:02:34,830
like a hard disk drive or a tape backup.

73
00:02:34,830 --> 00:02:37,440
This degaussing process renders the data on the device

74
00:02:37,440 --> 00:02:39,510
unreadable and irretrievable.

75
00:02:39,510 --> 00:02:41,370
Unlike overriding though which might leave

76
00:02:41,370 --> 00:02:43,380
a small possibility of data recovery,

77
00:02:43,380 --> 00:02:44,970
degaussing will completely erase

78
00:02:44,970 --> 00:02:47,220
the magnetic properties of the storage medium

79
00:02:47,220 --> 00:02:49,680
to ensure that the data is permanently destroyed.

80
00:02:49,680 --> 00:02:51,600
However, it's also important to note

81
00:02:51,600 --> 00:02:53,370
that once a device has been degaussed,

82
00:02:53,370 --> 00:02:55,170
it could no longer be used for storage

83
00:02:55,170 --> 00:02:57,180
because its fundamental ability to store data

84
00:02:57,180 --> 00:02:58,860
has now been eliminated.

85
00:02:58,860 --> 00:03:00,570
This method is especially valuable

86
00:03:00,570 --> 00:03:02,910
when devices are set to be discarded or recycled

87
00:03:02,910 --> 00:03:05,430
to ensure that no data remnants of sensitive information

88
00:03:05,430 --> 00:03:08,070
remains on that discarded storage device.

89
00:03:08,070 --> 00:03:10,110
Now, Secure Erase is our third method

90
00:03:10,110 --> 00:03:12,570
and Secure Erase is another sanitization technique

91
00:03:12,570 --> 00:03:15,030
that used to be very popular, and it was a precursor

92
00:03:15,030 --> 00:03:16,920
to the newer cryptographic erase technique

93
00:03:16,920 --> 00:03:18,030
that you're going to learn about.

94
00:03:18,030 --> 00:03:19,140
Now with Secure Erase

95
00:03:19,140 --> 00:03:20,790
we are aiming to completely delete data

96
00:03:20,790 --> 00:03:21,930
from a storage device

97
00:03:21,930 --> 00:03:23,640
while ensuring that it cannot be recovered

98
00:03:23,640 --> 00:03:26,130
using traditional recovery tools or methods.

99
00:03:26,130 --> 00:03:28,020
This method is typically going to be implemented

100
00:03:28,020 --> 00:03:30,030
at the firmware level of a storage device

101
00:03:30,030 --> 00:03:32,550
like a solid state device or a hard disk drive.

102
00:03:32,550 --> 00:03:34,530
When the Secure Erase command is issued

103
00:03:34,530 --> 00:03:36,840
the storage device's built-in erasure routine

104
00:03:36,840 --> 00:03:37,860
is going to be activated

105
00:03:37,860 --> 00:03:39,360
and it's going to purge all the data blocks

106
00:03:39,360 --> 00:03:42,150
to make the data irretrievable from that device.

107
00:03:42,150 --> 00:03:43,830
Overtime, some flaws were found

108
00:03:43,830 --> 00:03:45,180
in the Secure Erase technique

109
00:03:45,180 --> 00:03:46,680
and a newer, more secure technique

110
00:03:46,680 --> 00:03:49,650
known as Cryptographic Erase or CE was introduced

111
00:03:49,650 --> 00:03:51,360
to replace the Secure Erase technique

112
00:03:51,360 --> 00:03:53,640
in most of our modern storage devices.

113
00:03:53,640 --> 00:03:55,590
Now, Cryptographic Erase is going to leverage

114
00:03:55,590 --> 00:03:57,840
encryption technologies as its primary mechanism

115
00:03:57,840 --> 00:03:59,970
for doing data sanitization.

116
00:03:59,970 --> 00:04:02,490
Now, when data is initially stored on a given device

117
00:04:02,490 --> 00:04:05,400
it's going to be encrypted using cryptographic keys.

118
00:04:05,400 --> 00:04:07,440
During the cryptographic erasure process,

119
00:04:07,440 --> 00:04:10,110
instead of trying to erase the actual data on the device

120
00:04:10,110 --> 00:04:11,910
we simply are going to deliberately destroy

121
00:04:11,910 --> 00:04:13,950
or delete the encryption keys themself

122
00:04:13,950 --> 00:04:16,589
because without these keys, the data remains on the device

123
00:04:16,589 --> 00:04:18,000
but it's rendered unreadable.

124
00:04:18,000 --> 00:04:21,149
So in practical terms, it's now considered irretrievable.

125
00:04:21,149 --> 00:04:22,590
Now, one of the significant advantages

126
00:04:22,590 --> 00:04:23,940
of using cryptographic erase

127
00:04:23,940 --> 00:04:26,520
over traditional erasure methods is speed.

128
00:04:26,520 --> 00:04:27,810
Because with cryptographic erase

129
00:04:27,810 --> 00:04:30,030
we're only having to delete the encryption keys

130
00:04:30,030 --> 00:04:32,370
and not all of the data on a one or two

131
00:04:32,370 --> 00:04:34,410
or 10 terabyte hard disk drive.

132
00:04:34,410 --> 00:04:36,390
This makes the entire sanitization process

133
00:04:36,390 --> 00:04:37,800
really quick to perform

134
00:04:37,800 --> 00:04:40,440
and it can be done in less than about 30 to 60 seconds

135
00:04:40,440 --> 00:04:42,540
when you're doing a cryptographic erasure.

136
00:04:42,540 --> 00:04:45,180
Also, because our data remains encrypted and indecipherable

137
00:04:45,180 --> 00:04:46,620
without that description key

138
00:04:46,620 --> 00:04:48,450
the storage device can then be repurposed

139
00:04:48,450 --> 00:04:51,630
or resold without there being the risk of data leakage.

140
00:04:51,630 --> 00:04:53,820
Next, let's talk about destruction.

141
00:04:53,820 --> 00:04:57,030
Now, while sanitization is trying to make data unrecoverable

142
00:04:57,030 --> 00:04:58,560
destruction goes a step further

143
00:04:58,560 --> 00:05:00,540
by ensuring that the physical device itself

144
00:05:00,540 --> 00:05:02,700
is beyond recovery or reuse.

145
00:05:02,700 --> 00:05:05,280
The NIST guidelines recommend methods like shredding,

146
00:05:05,280 --> 00:05:08,130
pulverizing, melting, or incinerating storage media

147
00:05:08,130 --> 00:05:10,230
as possible forms of destruction.

148
00:05:10,230 --> 00:05:11,430
For instance, I used to work

149
00:05:11,430 --> 00:05:13,080
at the National Security Agency,

150
00:05:13,080 --> 00:05:14,430
and whenever we decommissioned our old,

151
00:05:14,430 --> 00:05:17,010
top secret workstations, we had to remove the hard drives

152
00:05:17,010 --> 00:05:19,560
from those machines and then have them physically shredded

153
00:05:19,560 --> 00:05:20,880
to prevent anyone from accessing

154
00:05:20,880 --> 00:05:22,860
our nation's top secret information.

155
00:05:22,860 --> 00:05:25,110
So if you're working in a high security environment

156
00:05:25,110 --> 00:05:27,120
that include secret or top secret data,

157
00:05:27,120 --> 00:05:29,670
usually data sanitization will not be considered

158
00:05:29,670 --> 00:05:32,490
secure enough for this kind of high security environment.

159
00:05:32,490 --> 00:05:35,010
Instead, we're going to use a data destruction technique

160
00:05:35,010 --> 00:05:37,950
like shredding, pulverizing, melting, or incinerating

161
00:05:37,950 --> 00:05:40,470
the storage device that is going to be used instead,

162
00:05:40,470 --> 00:05:42,480
depending on the type of media and the nature of data

163
00:05:42,480 --> 00:05:43,830
that it once held.

164
00:05:43,830 --> 00:05:45,750
Now, once the data has been sanitized

165
00:05:45,750 --> 00:05:47,550
or the storage device has been destroyed,

166
00:05:47,550 --> 00:05:49,410
we want to document that the asset disposal

167
00:05:49,410 --> 00:05:51,180
or destruction has been completed

168
00:05:51,180 --> 00:05:53,580
by following a certification process.

169
00:05:53,580 --> 00:05:55,080
According to the NIST standards

170
00:05:55,080 --> 00:05:56,790
certification is an act of proof

171
00:05:56,790 --> 00:05:59,640
that the data or hardware has been securely disposed of.

172
00:05:59,640 --> 00:06:01,590
The certification can be especially important

173
00:06:01,590 --> 00:06:03,270
for organizations who must comply

174
00:06:03,270 --> 00:06:05,970
with strict regulatory controls or those organizations

175
00:06:05,970 --> 00:06:07,770
that handle particularly sensitive data,

176
00:06:07,770 --> 00:06:10,620
such as top secret government data, financial information,

177
00:06:10,620 --> 00:06:13,200
or health records contained on your systems.

178
00:06:13,200 --> 00:06:15,390
With certification, we are not merely focused

179
00:06:15,390 --> 00:06:17,700
on the sanitization or destruction of the data

180
00:06:17,700 --> 00:06:19,440
but we also want to ensure that we can provide evidence

181
00:06:19,440 --> 00:06:21,570
that our organization is taking its data security

182
00:06:21,570 --> 00:06:24,090
posture very seriously by creating an audit log

183
00:06:24,090 --> 00:06:26,970
of the sanitization, disposal, or destruction process

184
00:06:26,970 --> 00:06:28,620
for a given data set.

185
00:06:28,620 --> 00:06:30,720
Now, when it comes to data, every piece of data

186
00:06:30,720 --> 00:06:33,660
has what's known as a lifecycle and that lifecycle begins

187
00:06:33,660 --> 00:06:35,580
when the data is first created and it ends

188
00:06:35,580 --> 00:06:38,100
when the data is being disposed of or destroyed.

189
00:06:38,100 --> 00:06:39,810
For this reason, it's important to consider

190
00:06:39,810 --> 00:06:41,130
your data retention requirements

191
00:06:41,130 --> 00:06:42,900
when you're developing your asset disposal

192
00:06:42,900 --> 00:06:44,580
and destruction policies.

193
00:06:44,580 --> 00:06:46,320
Now, data retention isn't about hoarding

194
00:06:46,320 --> 00:06:48,870
every piece of data indefinitely, but instead,

195
00:06:48,870 --> 00:06:51,450
we are focused on strategically deciding on what to keep

196
00:06:51,450 --> 00:06:52,770
and for how long.

197
00:06:52,770 --> 00:06:55,020
The data lifecycle is going to encompass stages

198
00:06:55,020 --> 00:06:57,660
from data creation, data processing, data archiving,

199
00:06:57,660 --> 00:06:59,640
and the eventual data destruction.

200
00:06:59,640 --> 00:07:02,130
But why should we retain data in the first place?

201
00:07:02,130 --> 00:07:03,330
Why not just delete everything

202
00:07:03,330 --> 00:07:04,950
when you no longer need to use it?

203
00:07:04,950 --> 00:07:06,960
Well, there's several reasons that might require us

204
00:07:06,960 --> 00:07:08,220
to retain data.

205
00:07:08,220 --> 00:07:09,960
Regulatory requirements, for example,

206
00:07:09,960 --> 00:07:11,730
might mandate that certain types of data

207
00:07:11,730 --> 00:07:14,010
like financial transactions or medical records

208
00:07:14,010 --> 00:07:16,560
be preserved for a specific period of time.

209
00:07:16,560 --> 00:07:18,660
Additionally, retained data could be valuable

210
00:07:18,660 --> 00:07:20,160
if your organization needs to be able

211
00:07:20,160 --> 00:07:22,590
to conduct historical analysis, trend prediction,

212
00:07:22,590 --> 00:07:24,810
or even to resolve some disputes.

213
00:07:24,810 --> 00:07:27,720
However, retaining everything is simply not feasible,

214
00:07:27,720 --> 00:07:29,280
nor is it advisable.

215
00:07:29,280 --> 00:07:31,320
Storing vast amounts of data comes with a cost

216
00:07:31,320 --> 00:07:33,450
in terms of tangible things like server costs

217
00:07:33,450 --> 00:07:35,850
and storage costs as well as intangible costs

218
00:07:35,850 --> 00:07:37,560
like increasing the complexity of your data

219
00:07:37,560 --> 00:07:39,030
and your system management.

220
00:07:39,030 --> 00:07:41,640
Additionally, the more data that your organization retains,

221
00:07:41,640 --> 00:07:43,980
the larger a target your data is going to become

222
00:07:43,980 --> 00:07:45,840
for a cyber threat actor.

223
00:07:45,840 --> 00:07:48,030
Personally, I like to think about this mantra

224
00:07:48,030 --> 00:07:50,040
when I'm developing my data retention policies

225
00:07:50,040 --> 00:07:51,480
within my organizations.

226
00:07:51,480 --> 00:07:54,300
The more you store, the more you must secure.

227
00:07:54,300 --> 00:07:56,340
So why don't we just retain everything?

228
00:07:56,340 --> 00:07:58,410
Well, even though storage costs have been reduced

229
00:07:58,410 --> 00:08:00,570
over the years it's still a pretty significant expense

230
00:08:00,570 --> 00:08:01,890
when you try to keep everything,

231
00:08:01,890 --> 00:08:03,570
especially for larger organizations

232
00:08:03,570 --> 00:08:05,280
who store petabytes of data.

233
00:08:05,280 --> 00:08:06,960
Moreover, storing data indefinitely

234
00:08:06,960 --> 00:08:09,000
can lead to clutter that makes data retrieval

235
00:08:09,000 --> 00:08:12,090
and analysis much more cumbersome and time consuming.

236
00:08:12,090 --> 00:08:15,090
Another often overlooked aspect is data protection.

237
00:08:15,090 --> 00:08:16,110
Every piece of data

238
00:08:16,110 --> 00:08:18,270
no matter how trivial needs to be protected

239
00:08:18,270 --> 00:08:19,980
from potential data breaches.

240
00:08:19,980 --> 00:08:21,120
The more data you have

241
00:08:21,120 --> 00:08:22,650
the more expansive your security measures

242
00:08:22,650 --> 00:08:23,700
are going to need to be.

243
00:08:23,700 --> 00:08:25,770
And this in turn translates into higher costs

244
00:08:25,770 --> 00:08:28,350
and the need to make additional resource allocations.

245
00:08:28,350 --> 00:08:30,720
So remember, asset disposal and decommissioning

246
00:08:30,720 --> 00:08:33,059
is an important process that must be considered

247
00:08:33,059 --> 00:08:34,860
so your assets can be properly handled

248
00:08:34,860 --> 00:08:36,390
throughout their entire lifecycle

249
00:08:36,390 --> 00:08:38,850
especially during retirement and disposal.

250
00:08:38,850 --> 00:08:40,440
By following standardized procedures,

251
00:08:40,440 --> 00:08:41,490
like the guidelines presented

252
00:08:41,490 --> 00:08:43,919
by the National Institute of Standards and Technology,

253
00:08:43,919 --> 00:08:45,690
we can ensure that we're not just in compliance

254
00:08:45,690 --> 00:08:48,390
but we're also helping to increase our peace of mind.

255
00:08:48,390 --> 00:08:51,300
Our end goal here is clear, dispose of assets securely,

256
00:08:51,300 --> 00:08:53,730
retain data judiciously, and ensure the integrity

257
00:08:53,730 --> 00:08:56,643
and reputation of our organizations remain untarnished.

