Inventory the life of a copy
Disabling an application does not automatically end its information lifecycle. A useful inventory includes the primary database, backups, replicas, exports, ticket attachments and relevant temporary areas. Associate purpose, owner, location, data class, dependencies and disposition conditions. In the lab, the database is copied and a CSV exported before one source row is removed. The source query no longer finds it, but the backup and CSV retain it. This does not mean every architecture behaves identically; it demonstrates that an independent copy is not removed by an operation elsewhere. Migration completion should explicitly account for retained destinations.
Expiry, preservation instruction and unknown state
Disposition depends on applicable conditions rather than file age alone. The exercise uses a fictional organizational rule: expired retention and confirmed absence of preservation requirements allow a disposal proposal; an active instruction requires retention; unknown metadata requires review. It does not interpret an empty field as authorization. Distinguish eligibility for disposal from approved execution. At work, obtain applicable policy and responsible specialists to resolve conflicts, including preservation obligations. An exception should have scope, owner and review so a temporary need does not become indefinite retention of every copy. These examples establish neither universal legal deadlines nor a bank’s internal procedures.
Choose a technique for the actual medium
Sanitization aims to make access to target data infeasible for a considered effort level. Choosing clear, purge or destroy depends on medium, sensitivity, control and disposition under policy. Deleting a file removes a logical reference; by itself it does not establish treatment of blocks, remapped areas or copies. Do not automatically transfer a magnetic-disk procedure to an SSD, virtualized storage or a cloud service. Request device- and technique-appropriate characteristics and evidence. If equipment will be reused, include that requirement in the decision. Destruction may prevent reuse, while another method is acceptable only if it achieves the required protection and has been correctly applied.
Cryptographic erase and recoverable copies
Cryptographic erase depends on conditions that must be established. Identify data actually encrypted, keys capable of recovering it, implementation quality and relevant recovery paths. A key deleted from one system may remain in backup, escrow or another manager. Record how these copies were addressed without confusing rotation with destruction. If a plaintext copy remains outside scope, deleting a key does not retroactively protect it. In a decommissioning project, relate each claim to the assets and keys covered. A screenshot showing one absent key or a tool result without target and operation identification is insufficient evidence.
Verify execution and decide acceptance
NIST SP 800-88 Rev.2 distinguishes inspecting a technique’s outcome from deciding whether sanitization was effective. Retain medium identity, method, tool, outcome, errors and acceptance owner. A completed status can support verification, but anomalies and suitability for the objective still need assessment. Evidence for one device does not automatically cover another serial number. A hash helps compare bytes with a reference; it does not establish that other copies disappeared. The lab only creates, exports, copies and logically deletes synthetic data. Cleanup of its temporary folders is not presented as physical sanitization. To close the project, reconcile planned assets against documented decisions and exceptions.
# Run from the project root with Python 3:
python3 content/labs/cissp-asset-lifecycle/run.py --output /tmp/cissp-assets-evidence.json
# Compare checks and observations in the evidence.
# All records are synthetic. No media sanitization is performed.
The source has seven rows while backup and CSV retain eight. The deletion record must explain scope without claiming every copy disappeared.
Common pitfalls
DELETE as sanitization; absent local key as all keys destroyed; completed as acceptance; unknown expiry as authorization.
Related topics: Governance and risk · Key custody and recovery · Evidence and assessment
Track copies and accept only the scope supported by evidence.
Reference: Guidelines for Media Sanitization · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29