Firmware-Based Clear under NIST SP 800-88 Rev. 2 and IEEE 2883-2022

Applies to: Pro, Enterprise and Audit

Overview

A completed firmware operation can support a Clear sanitization result when it processes the required user-addressable storage through a supported device interface and DriveErase records sufficient evidence of target identity, coverage, command completion and result status.

Selecting a firmware-based method does not automatically produce a Clear result. DriveErase evaluates the operation that actually completed and withholds a positive standards result when the required conditions cannot be established.

NIST SP 800-88 Revision 2 Clear Classification

NIST Clear applies logical techniques to all user-addressable storage locations and is intended to protect against simple, non-invasive recovery through the interface normally available to the user.

Clear can be performed using ordinary read/write commands or other supported device-interface operations. The appropriate technique depends on the storage technology and the capabilities exposed by the device.

NIST SP 800-88 Revision 2 defines the required outcome but generally refers technology-specific command selection to standards such as IEEE 2883-2022.

IEEE 2883-2022 Clear Classification

IEEE 2883-2022 defines protocol-specific Clear procedures for ATA, SCSI and NVMe storage.

Depending on the device and command path, a Clear technique can include:

  • Host overwrite of the required addressable range
  • ATA Security Erase in Normal Erase mode
  • Qualifying SCSI device-interface operations
  • Qualifying NVMe Format NVM operations
  • Approved vendor-specific operations

The exact requirements vary according to the device interface and technique used.

Firmware Clear in DriveErase

DriveErase can evaluate a firmware operation for a Clear result when the completed technique is consistent with the applicable Clear requirements.

Examples include:

  • ATA Security Erase completed in Normal Erase mode
  • An eligible NVMe Format NVM User Data Erase operation for which the required scope can be established
  • Another supported operation that meets the applicable IEEE Clear conditions

A positive result can be withheld when:

  • The target identity cannot be confirmed
  • The command does not complete successfully
  • Required device areas or namespaces cannot be shown to be covered
  • The device reports an error or incomplete state
  • The controller or connection path obscures necessary evidence
  • The completed technique cannot be classified conclusively
  • Required result information is unavailable

Clear does not automatically mean Purge

A Clear result describes protection against recovery through the normally available interface. It should not be represented as Purge unless the completed technique also satisfies the more demanding Purge requirements.