DoD and HMG Legacy Overwrite Profiles

Applies to: All editions

Purpose

DriveErase includes historically named multi-pass and single-pass profiles for compatibility with procedures that still reference those sequences. These names identify the configured pattern sequence. They do not establish current endorsement, third-party certification, or applicability to every storage technology.

DoD 5220.22 M

The three-pass profile writes:

  1. 0x00;
  2. 0xFF;
  3. cryptographically generated random data.

Because the final pass is random and the complete stream is not retained, fixed-pattern sampled verification is not available after the final pass.

DoD 5220.22 M ECE

The seven-pass profile writes:

  1. 0x00;
  2. 0xFF;
  3. random data;
  4. 0x00;
  5. 0xFF;
  6. random data;
  7. random data.

The random final pass prevents later sampled comparison with a retained final fixed pattern.

HMG Infosec Standard No. 5 — Higher

The Higher profile uses the practical three-pass sequence:

  1. 0x00;
  2. 0xFF;
  3. random data.

HMG Infosec Standard No. 5 — Lower

The Lower profile performs one all-zero pass. Its fixed final pattern permits sampled verification of the addressable logical range.

Selection guidance

Use a legacy profile only when an approved procedure specifically requires that sequence. For modern risk-based sanitization, method suitability, device technology, full coverage, firmware capabilities, verification, errors, and disposition should take priority over historical pass count.

Multi-pass overwrite substantially increases duration and total writes. On flash storage it still does not establish coverage of hidden controller-managed areas.