38 Chapter 2 ■ Asset Security (Domain 2)
- Ben is following the National Institute of Standards and Technology (NIST) Special Pub-
lication 800-88 guidelines for sanitization and disposition as shown here. He is handling
information that his organization classified as sensitive, which is a moderate security cat-
egorization in the NIST model. If the media is going to be sold as surplus, what process
does Ben need to follow?
Security
Categorization
LowSecurity
Categorization
ModerateSecurity
Categorization
HighReuse
Media?Reuse
Media?Leaving
Org
Control?Leaving
Org
Control?Leaving
Org
Control?NoNoNoNoClearClear ValidateExitPurgePurgeDestroyDestroyYesNoYesYesYes YesDocumentSource: NIST SP 800-88.A. Destroy, validate, document
B. Clear, purge, document