Protecting data in the retired assets is a complex issue that goes way beyond data destruction. It encompasses a variety of critical aspects. Based on our own experience and what we have learned from our stringent corporate customers, we have developed the following best practices blueprint for CIOs to select a technology asset disposal service provider.
What is the service provider’s chain-of-custody program?
The chain-of-custody program usually starts before receiving assets at the service provider’s facility. It involves a holistic view of the service provider’s entire receiving, processing and disposal process. The service provider must have detailed procedures and be able to answer these questions and many more.
- If transportation is the responsibility of the service provider, does the service provider have a logistics security program in place?
- What is the service provider’s facility security infrastructure?
- What is the service provider’s receiving procedure? o What is the service provider’s general processing procedure?
- For assets to be remarketed, do they only remarket tested and functional units so as not to violate domestic and international laws and/or certification standards such as Responsible Recycling (R2) and e-Steward?
- For assets to be recycled, do they have a good process in place either via manual demanufacturing or mechanical shredding?
What is the service provider’s procedure in executing a data destruction management program?
This is an extremely important issue whereby companies need to exercise highest due diligence via both paper and on-site audit. The critical areas warranting special focus include:
- Does the service provider perform the data sanitization in a secured area with access control?
- What is their data sanitization procedure?
- Does the service provider also have software and procedures for enterprise data storage units, cellular phones and tablets?
- Does the service provider have a NAID Computer Hard Drive Sanitization and Destruction certification?
For in-depth information, please read “Securing the Back Door on Data Security: Best Practices Blueprint on Technology Asset Disposition for CIOs.”