Retiring old hard drives: from 'wipe it with software' to a written policy
When a company retires an old computer through its asset write-off process, what happens to the data on the hard drive easily becomes one of those things “everyone knows needs doing, but nobody ever wrote down.” During a routine fixed-asset inventory, the team went back and reviewed the existing policy on this, and confirmed exactly that: the long-standing practice had been to pull the drive and wipe it with software, but there was no documented standard for what that actually meant - which tool, how many passes, what counted as sufficient.
From “good enough” to two explicit options
Rather than continuing an undocumented habit, the team formalized it into two explicit, either/or options:
- Software wipe to the DoD 5220.22-M standard (a US Department of Defense data-sanitization spec that overwrites data across multiple passes so it can’t be recovered through ordinary means), executed with an open-source tool like DBAN;
- Physical destruction - pulling the drive and destroying it outright, removing any possibility of data recovery, with the act of destruction itself documented.
“It’s been wiped” and “we can prove it’s been wiped” are two different claims
The physical-destruction path also raised a practical question: who actually does the destroying - does the outsourced asset-disposal vendor destroy the drives on-site, or does the vendor pull the drives and hand them back for the internal team to destroy themselves? Both approaches work; the real distinction is whether the data has been dealt with before it ever leaves the company’s control, and the right choice depends on how much trust exists in the vendor and how much the internal team can handle itself.
Why “wipe it” alone isn’t enough - the case for a written policy
- No standard means no consistency. Different people handling this task apply wildly different levels of rigor - some run one pass and call it done, others run a full professional tool cycle. The more devices retired, the more this inconsistency compounds as risk;
- No record means no evidence at audit time. The tail end of a write-off process usually needs a signed disposal form and destruction certificate - if nobody can say clearly which method was used to handle the data, that record is incomplete by definition;
- Retirement volume scales with company growth. Retiring a handful of computers at a time makes an unstandardized process cheap to get away with; once the write-off list grows to dozens or hundreds of units a year, the absence of a standard directly amplifies data-leakage exposure.
Lessons
- “This is how we’ve always done it” is not the same as “this is a standard process.” Many long-running habits only look “good enough” because nothing has gone wrong yet - a routine inventory or audit is often the best occasion to make an implicit habit explicit and write it into formal policy;
- Neither data-destruction path (software wipe vs. physical destruction) is inherently right or wrong, but one has to be chosen and the standard has to be written down. A software wipe is more sustainable and lets the drive be reused; physical destruction is more absolute and leaves zero recovery possibility. Which to choose depends on the device’s sensitivity level and the company’s resources;
- For asset disposal involving an external vendor, “who touched the data and when” needs to be explicitly recorded. Regardless of which destruction method is chosen, the destruction certificate and disposal record should be treated as a required part of the process, not an optional attachment.