NIST 800-88 and CJIS
The FBI CJIS Security Policy relies on recognized media sanitization standards to ensure that information cannot be recovered after disposal. The industry-standard framework for media sanitization is NIST SP 800-88 Revision 2, which defines methods for rendering stored information inaccessible and unrecoverable. [csrc.nist.gov], [nvlpubs.nist.gov]
NIST identifies three sanitization outcomes:
Clear
Logical removal of data that protects against routine recovery methods.
Purge
Sanitization methods designed to prevent recovery even through advanced forensic techniques.
Destroy
Physical destruction of the storage media itself, eliminating any possibility of future use or recovery.
For CJIS-regulated environments, organizations commonly employ Purge or Destroy methods when equipment containing Criminal Justice Information is retired.
CJIS Requirements for Data Disposal
CJIS requires organizations to protect Criminal Justice Information throughout its lifecycle, including when electronic media is retired, repurposed, sold, recycled, or destroyed. The objective is simple:
Criminal Justice Information must never be recoverable by unauthorized individuals.[le.fbi.gov], [CJIS_Secur...4_20231220 | PDF]
Storage devices that may contain CJI include:
Desktop computers
Laptops
Servers
Hard drives
Solid-state drives (SSDs)
USB drives
Mobile devices
Multifunction printers and copiers
Backup media
Before any device leaves organizational control, the information it contains must be properly sanitized or destroyed.
