NIST SP 800-88 is the document most modern erasure policy is written against, and its central idea is one that older standards missed: the right method depends on the media, and on what you intend to do with the asset afterwards. It defines three levels, and the difference between them is not thoroughness. It is who you are defending against.
Clear
Clear protects against recovery using the device's own interfaces — the operating system, a file recovery tool, anything that reads the drive the ordinary way. A single overwrite pass achieves it on a hard disk. It is appropriate when the asset is staying inside your organisation, moving between departments, or being reissued to another user.
Purge
Purge protects against laboratory recovery — someone who will take the media apart and read it at a level the interface does not expose. On a hard disk that means overwriting the whole addressable surface, and on flash it means using the drive's own sanitize or cryptographic erase command rather than writing patterns at it. Purge is the level for an asset leaving your control: sold, returned, donated or recycled.
Destroy
Destroy is physical: shredding, disintegration, incineration. It is the answer when the media cannot be trusted to sanitize itself — a drive that refuses the command, a device with failed sectors, or a classification level whose policy simply does not permit reuse.
Why the distinction matters commercially
Because two of the three preserve the asset's value and one does not. An organisation that destroys everything is safe and is also throwing away resale value on hardware that could have been purged and sold. An organisation that clears everything is efficient and is also handing laboratory-recoverable drives to strangers. Deciding per asset, and recording which level was applied, is the whole of the discipline.
Clear, Purge and Destroy are not weak, medium and strong. They are three different threat models.
The standards register in Data Sanitization Pro names the level each method satisfies, so the certificate says Purge rather than merely naming a pass count — which is the part an auditor can actually act on.



