Mitigation
NCSC (CESG) CPA
6
DEP.M137
Confidentiality
Accountability
7
DEP.M137
Integrity
8
Confidentiality
Accountability
9
DEP.M703
Confidentiality
Accountability
Risk
Best Practice
Sanitisation
The sanitisation methods which are employed to process any
iStorage secure drive should be supported by documented
Methods
sanitisation procedures and Security Operating Procedures
(SyOps);
Such procedures should follow appropriate processes rele-
vant to the media type and any Protective Marking, or other
Government Classification of the data asset being sanitised to
meet as a minimum HMG Standards.
The selected Service Provider must demonstrate that these
procedures are followed in practice.
NCSC (part of GCHQ) advice available at the following URL:
https://www.ncsc.gov.uk/index/topic/164
Sanitisation
All Sanitisation/Destruction iStorage secure drives products
and Disposal
should be conducted in line with Manufacturer's documented
operating procedures, user guides and any published Security
Procedures;
The personnel or teams who are conducting the sanitisation,
or secure disposal process should be trained in the correct
usage of such equipment;
Processes must be in place to verify that equipment is being
used correctly and in accordance with the manufacturers
recommendations.
Reissue
On occasions where the iStorage secure drive has been sub-
of Media
jected to sanitisation and is required for reissue to a new user,
custodian, or department, checks should be conducted prior
to issue to assure that the media is fully blank;
An iStorage secure drive user manual should be issued to the
recipient user, with clear instructions of secure operational
use;
The issue of the iStorage secure drive should be fully ac-
counted for and entered in an asset register.
Loss, Theft,
Ensure that a process exists to support notification to man-
agement of theft, loss, or compromise of the iStorage secure
Compromise
drive awaiting processing;
Where Protectively Marked or Government data assets are
stored on the iStorage, seek advice from the appropriate
authority of agency;
www.istorage-uk.com
#37