What the document is, and what it is not
NIST SP 800-88 Revision 2, Guidelines for Media Sanitization is the United States reference for removing data from storage media so that it cannot be recovered. It is published by NIST, it is free, and anybody selling you sanitization has read it or should have.
It is guidance, not law. It becomes an obligation for one organization through something else: a contract, a sector regulator, a certification scheme, an insurer, or an internal policy that adopts it. Which of those reaches you is a question about your organization and not about the document, and a vendor telling you that NIST requires something of you is describing a route they have not named.
The four things Revision 2 moved
Summarised from the publication notice. The document itself is the authority, and it is worth an hour of anybody’s time who signs off on a decommission.
1. From techniques to a program
- Revision 1.
- Revision 1 read as a catalog: here are the media, here are the methods.
- Revision 2.
- Revision 2 shifts the focus toward establishing an agency or enterprise media sanitization program. The unit of analysis stops being the drive and becomes the organization's rule for drives.
What that means for you. If a vendor proposes a method before asking who classified your data, they are answering the Revision 1 question. The current one starts earlier.
2. From described procedures to current standards
- Revision 1.
- Revision 1 described the procedures inside the document itself.
- Revision 2.
- Revision 2 replaces those descriptions with recommendations to comply with the latest relevant standards, which is a maintenance decision: storage media change faster than a reference document can be revised.
What that means for you. Work sold as being “to NIST 800-88” now has to name the execution standard it actually follows. Without that, the reference has become a label.
3. Validation becomes part of the text
- Revision 1.
- Revision 1 concerned itself principally with performing sanitization.
- Revision 2.
- Revision 2 introduces sanitization validation: confirming that the operation achieved its purpose, judged against the confidentiality and sensitivity of the data involved.
What that means for you. This is the difference between a vendor asserting that drives were wiped and demonstrating it. On a lot of several thousand, it is the only part an auditor examines.
4. Logical sanitization and cloud enter scope
- Revision 1.
- Revision 1 was written for media you could hold.
- Revision 2.
- Revision 2 addresses modern storage environments, including logical sanitization where there is no physical device to destroy.
What that means for you. A data hall exit that leaves data in an associated cloud tenancy is not complete, and the exit plan has to account for it in writing.
The through-line
Both of the substantive changes push in the same direction: away from what was done to a device, and toward what the organization can show. A program rather than a technique. Validation rather than assertion. That is also, not by coincidence, what somebody auditing your exit will ask for, and it is why what your certificate of destruction contains matters more than which machine processed the drives.