Maintain Chain of Custody for Erasure Operations

Applies to: All editions; Enterprise and Audit provide the most detailed structured report

Purpose

Chain of custody links authorization, target identity, operator action, software evidence, review, and final disposition. CertErase contributes technical records but does not create the entire governance process.

Minimum control set

Before the operation, record:

  • Case, ticket, or disposal identifier;
  • Data owner and authorizing person;
  • Legal-hold and retention check;
  • Target asset and storage location;
  • Data classification;
  • Approved sanitization outcome and technique;
  • Product version and edition;
  • Expected profile and controls;
  • Operator and reviewer;
  • Required evidence and retention period.

During the operation:

  • Control physical and logical access;
  • Prevent target substitution;
  • Record start and end time in UTC;
  • Preserve item-level warnings and failures;
  • Document cancellation or interruption;
  • Do not edit the raw operational log.

After the operation:

  • Export the required log or report;
  • Validate that its scope matches the authorization;
  • Record unresolved items explicitly;
  • Store evidence in a controlled repository;
  • Record an integrity hash or immutable repository identifier;
  • Obtain operator and reviewer sign-off;
  • Update the asset or case record;
  • Document reuse, return, transfer, or destruction of the device.

Separation of duties

For high-risk data, use separate operator and reviewer roles. The reviewer should confirm the target identity, profile, verification state, result, and assurance boundary rather than merely signing the report.

Evidence retention

Retain only the evidence necessary for accountability. Reports can contain sensitive paths, user names, system details, and asset information. Apply access control, retention limits, and secure disposal to the evidence itself.