Applies to: All editions
Purpose
Use this page to define what a DriveErase result means and to establish the controls required before an irreversible operation.
Sanitization scope
DriveErase targets the selected physical storage device. The exact scope depends on the method:
- Overwrite-based sanitization writes to the logical address range exposed through the active controller path.
- Firmware-based sanitization requests a supported operation from the device firmware and records the mode and result returned by that workflow.
- Firmware with overwrite fallback attempts the firmware method first and uses the selected overwrite method when the firmware operation cannot complete.
No single result should be assumed to cover other copies of the data. Backups, snapshots, replicas, cloud synchronization, storage-array copies, removable copies, and application-level exports require separate treatment.
Flash-media limitations
SSDs, NVMe devices, USB flash drives, and memory cards manage physical storage internally. Wear levelling, over-provisioning, remapped blocks, controller caches, and retired cells can place prior data outside the logical range available to ordinary host writes.
For a directly attached, supported SSD or NVMe device, a compatible firmware method can provide stronger device-level coverage than host overwrite. An overwrite result on flash media applies to the exposed logical range and should not be represented as proof that every hidden or retired physical location was processed.
HDD considerations
A complete successful overwrite with the required verification can provide strong assurance for the addressable range of a functioning magnetic hard disk. Unreadable sectors, controller-remapped regions, incomplete writes, failed verification, or interrupted execution reduce that assurance and are recorded in the result.
Operator responsibilities
Before starting:
- Obtain authorization for the specific asset and data classification.
- Confirm that retention periods, legal holds, incident-response needs, and backup requirements permit destruction.
- Identify the device by model, serial number, capacity, and physical context—not by disk number alone.
- Disconnect unrelated storage where practical.
- Record custody, asset, ticket, and operator information under organizational procedure.
- Ensure stable power and sufficient time for the selected method and health test.
- Confirm that no required encryption keys, recovery material, or configuration data remain only on the target.
- Review all warnings before confirming the restart.
Interpreting success
A green or successful erasure status means the configured operation completed according to its recorded result. A standards-related compliance statement is issued only when the method-specific criteria represented by that statement are satisfied. Method names alone are not compliance evidence.
When destruction may be required
Logical or firmware sanitization may be unsuitable where:
- The device is physically damaged or cannot be addressed reliably;
- Controller access prevents the required command or coverage;
- The organization’s policy requires destruction for the data classification;
- Hidden-area coverage cannot be established to the required assurance level;
- The device will leave custody and the residual risk remains unacceptable.
In those cases, follow the organization’s approved physical-destruction and chain-of-custody process.
