Applies to: Pro, Enterprise and Audit
Overview
A firmware operation can support a Purge result when it uses an eligible device-level technique that makes recovery of the target data infeasible using state-of-the-art laboratory techniques while leaving the storage device potentially reusable.
Purge requires more than successful command completion. The completed technique, device capabilities, command scope and supporting evidence must satisfy the applicable conditions.
NIST SP 800-88 Revision 2 Purge Classification
NIST Purge can use logical or physical techniques. For reusable electronic storage, relevant logical techniques can include:
- Device-level overwrite
- Block erase
- Cryptographic erase
These techniques commonly use dedicated standardized sanitization commands that apply storage-specific functions and can reach beyond the abstraction of ordinary host read/write commands.
NIST advises consulting IEEE 2883 for the technology-specific conditions under which these techniques qualify as Purge.
IEEE 2883-2022 Purge Classification
IEEE 2883-2022 defines Purge procedures for ATA, SCSI and NVMe storage. Depending on the protocol and device, eligible techniques can include:
- ATA Sanitize Block Erase
- ATA Sanitize Overwrite
- Qualifying ATA Enhanced Security Erase
- SCSI Sanitize Block Erase
- SCSI Sanitize Overwrite
- Qualifying cryptographic erase
- Supported NVMe sanitize operations
Not every device supports every technique, and not every implementation provides enough evidence for a positive Purge result.
Firmware Purge in DriveErase
DriveErase can evaluate a firmware operation for a Purge result when the completed technique and recorded evidence satisfy the applicable conditions.
For example:
- A successfully completed SCSI Sanitize Block Erase can have Purge applicability
- A supported ATA Sanitize Block Erase or device-level Sanitize Overwrite can have Purge applicability
DriveErase withholds a positive Purge result when:
- The firmware operation does not complete successfully
- The device or command does not provide the required scope
- Cryptographic erase prerequisites cannot be established
- Required vendor assurance is unavailable
- Full subsystem, namespace or controller-associated coverage cannot be confirmed
- The completed technique cannot be conclusively classified
- Required execution evidence is incomplete
Effect of overwrite fallback
When a firmware operation fails and DriveErase completes the job through host overwrite fallback, the final standards result is based on the overwrite operation that actually completed.
An overwrite fallback does not inherit the Purge classification of the unsuccessful firmware method. On flash storage, the fallback normally covers only the logical range exposed through the controller.
