Choose a CertErase Erasure Method

Applies to: Profile availability depends on edition

What an erasure method controls

An erasure method defines the overwrite passes applied to the normal data stream of each selected file. A pass can write a fixed byte pattern or random data. Supporting controls like verification, alternate data streams, file-name changes, timestamp handling, metadata churn, and free-space wiping, are configured separately.

Available erasure methods

CertErase provides the following software overwrite profiles:

  • NIST SP 800-88
  • NIST SP 800-88 (3 passes)
  • IEEE 2883-2022
  • IEEE 2883-2022 (3 passes)
  • DoD 5220.22-M
  • DoD 5220.22-M (ECE)
  • NAVSO P-5239-26
  • RCMP TSSIT OPS-II
  • HMG IS5 Baseline
  • HMG IS5 Enhanced
  • AFSSI-5020
  • BSI/VSITR
  • Peter Gutmann
  • Schneier 7-Pass
  • AR 380-19
  • NCSC-TG-025
  • Simple 1 Pass Random
  • Random Byte Overwrite 3x
  • Aperiodic Random Overwrite
  • NSA 130-1
  • OPNAVINST 5239.1A
  • GOST R 50739-95
  • AFNOR NF Z74-101
  • JIS TR X 0008-1993
  • CSEC ITSG-06
  • Single-pass 0xFF
  • Hybrid Secure
  • Random N-pass

How to choose

Use the organization’s current sanitization policy and media-specific risk assessment. In many logical overwrite scenarios, verification and complete target coverage are more consequential than repeating large numbers of legacy passes. More passes increase time and device writes but do not solve limitations such as flash wear leveling, remapped sectors, snapshots, or inaccessible replicas.

A sensible decision sequence is:

  1. Classify the data and identify the required protection level;
  2. Identify the storage technology and whether logical overwrite is an approved technique;
  3. Identify all copies, including alternate streams, snapshots, backups, synchronization targets, and replicas;
  4. Choose the approved profile;
  5. Enable required verification and metadata controls;
  6. Define the evidence and review process;
  7. Test on representative media.

Standards-labelled profiles

A profile name describes CertErase’s configured overwrite recipe. It does not by itself establish compliance with the named document or authority. Some names refer to historical guidance, and current standards can require decisions, validation, documentation, and media-specific actions beyond software overwrite.

Use the version-specific CertErase profile specification to identify the exact pass sequence, pattern type, verification behaviour, and known limitations of a method. Record the installed product version with every controlled operation.

Random N-pass

The Random N-pass profile allows an operator to select a pass count. Use this only under an approved procedure. Arbitrarily increasing the count is not a substitute for selecting an appropriate sanitization technique.