Policy Number 7.303
Supersedes Policy Dated: October 3, 2003
Effective Date: October 3, 2003
Review Date: June 3, 2008
Title of Policy: Disk Sanitizing Policy for Workstations
Purpose of Policy: To maintain data confidentiality by preventing access to information previously stored on workstations transferred to new users or destined for surplus.
Person(s) with Primary Responsibility:
Managers of Desktop Support Staff
Approved:
Chief Information Officer
Disk Sanitizing Policy
Before a state-owned workstation is sent from ECU to surplus, the non-removable hard drive(s) shall be “sanitized” (i.e., all data removed in a manner that prevents subsequent recovery) before the computer leaves the ECU campus. If a workstation is transferred from one primary user to another, its hard drive(s) shall be sanitized at the time of transfer.
The method for sanitizing hard drives shall be approved by ITCS and comply with applicable security guidelines established by the United States Department of Defense. ITCS staff shall follow the Disk Sanitizing Procedure. Users should ensure that data covered by the North Carolina Records Retention Policy is copied from computers and appropriately stored before their disks are sanitized.