NIST 800-88 and CJIS

The FBI CJIS Security Policy relies on recognized media sanitization standards to ensure that information cannot be recovered after disposal. The industry-standard framework for media sanitization is NIST SP 800-88 Revision 2, which defines methods for rendering stored information inaccessible and unrecoverable. [csrc.nist.gov], [nvlpubs.nist.gov]

NIST identifies three sanitization outcomes:

Clear

Logical removal of data that protects against routine recovery methods.

Purge

Sanitization methods designed to prevent recovery even through advanced forensic techniques.

Destroy

Physical destruction of the storage media itself, eliminating any possibility of future use or recovery.

For CJIS-regulated environments, organizations commonly employ Purge or Destroy methods when equipment containing Criminal Justice Information is retired.

CJIS Requirements for Data Disposal

CJIS requires organizations to protect Criminal Justice Information throughout its lifecycle, including when electronic media is retired, repurposed, sold, recycled, or destroyed. The objective is simple:

Criminal Justice Information must never be recoverable by unauthorized individuals.[le.fbi.gov], [CJIS_Secur...4_20231220 | PDF]

Storage devices that may contain CJI include:

  • Desktop computers

  • Laptops

  • Servers

  • Hard drives

  • Solid-state drives (SSDs)

  • USB drives

  • Mobile devices

  • Multifunction printers and copiers

  • Backup media

Before any device leaves organizational control, the information it contains must be properly sanitized or destroyed.