Skip to main content

CMMC Pause: What DoW & Primes Still Require

background

CUI Sanitization: How to Destroy CUI and Sanitize Media the Right Way

  • cui
  • CUI Sanitization: How to Destroy CUI and Sanitize Media the Right Way

When a document, drive, or device containing CUI is no longer needed, you can't just throw it away, and you can't just hit delete. The governing rule, 32 CFR 2002.14, sets a clear standard: CUI must be destroyed in a way that makes it unreadable, indecipherable, and irrecoverable. 

So how do you actually do that? 

This article covers CUI sanitization for paper, digital media, and any equipment leaving your building.

The CUI destruction standard

Under 32 CFR 2002.14, destruction of CUI follows a specific order. 

First, check whether the law, regulation, or government-wide policy behind the CUI's category specifies a destruction method; if it does, that method is required. 

If it doesn't, you must use one of two approved paths: the guidance in NIST SP 800-88, Guidelines for Media Sanitization (along with the related NIST SP 800-53 controls), or any destruction method approved for classified national security information. NIST SP 800-88 is the standard nearly every contractor follows.

The test in every case is the same: after destruction, the CUI must be unreadable, indecipherable, and irrecoverable. Not just inconvenient or difficult to recover, completely irrecoverable.

There are two important points that should be clarified when it comes to CUI sanitization. 

  • Sanitization isn't the same as decontrol. Destroying a copy of CUI doesn't change the status of the information itself, and destroying CUI is not the same as decontrolling it. Only the designating agency can decontrol CUI. 
  • CUI status doesn't override records retention. If a document containing CUI is also a record you're required to keep, under a records schedule or your contract, you can't destroy it early just to reduce your CUI footprint. Destruction happens when disposition rules allow it, and then it happens to the sanitization standard.

Destroying paper CUI

For paper CUI, destruction that meets the standard above means cross-cut shredding. Per DCSA guidance for industry, shredders and shredding services must comply with NIST SP 800-88, destroying documents to particles of 1mm x 5mm. That's the same particle specification used for classified paper, and it's far finer than a typical office strip-cut shredder produces.

Intact CUI in the trash, the recycling bin, or a standard shred-and-recycle bin that doesn't meet the particle spec is not acceptable. If you use a commercial shredding service, confirm in writing that its process meets the specification, and get certificates of destruction. 

Until destruction happens, discarded CUI is still CUI, and a dumpster is not a controlled environment.

Sanitizing digital media

For electronic storage, NIST SP 800-88 defines sanitization as rendering access to the target data infeasible for a given level of recovery effort, and it organizes methods into three categories:

  • Clear uses logical techniques, like overwriting, to sanitize data in user-addressable storage. It protects against simple, non-specialized recovery attempts and allows the media to be reused.
  • Purge uses stronger logical or physical techniques, such as cryptographic erase or degaussing, that make data recovery infeasible even with state-of-the-art laboratory methods, while potentially preserving the media for reuse.
  • Destroy physically destroys the media: shredding, disintegrating, pulverizing, incinerating, or melting, so it can never store data again.

Two issues tend to trip organizations up with sanitizing digital media. 

First, deleting files, emptying the recycle bin, and factory-resetting a device are not sanitization. Deleted data remains on the media and is routinely recoverable with basic tools. 

Second, solid-state drives and other flash storage don't respond to traditional overwriting the way spinning drives do. Because flash devices use spare cells and wear leveling, overwriting can't reach all the locations where data may live, which is why purge techniques like cryptographic erase, or outright physical destruction, are the reliable answers for SSDs, USB drives, and phones.

Where sanitization shows up in your compliance program

If you're implementing NIST SP 800-171, sanitization is a named requirement, not just good hygiene. The Media Protection family requires sanitizing or destroying system media containing CUI before disposal or release for reuse. That includes the retired laptop headed to resale, the copier being returned at end of lease (office copiers have hard drives), and the backup drives leaving service. 

The Maintenance family also adds a scenario that’s easy to miss: equipment removed for off-site maintenance must be sanitized of any CUI first. If a server is going back to the vendor for repair, the CUI has to come off before it leaves.

CMMC assessments require evidence of compliance, so document your CUI sanitization practices: what was sanitized, when, by what method, and how it was verified. If a third party performs destruction, keep their certificates. A simple sanitization log turns an invisible practice into defensible proof.

Loading...