Sanitizing / Purging
Sanitizing, also described as purging, was intended for reuse in an environment that did not provide an acceptable level of protection for the previous data.
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
Historical U.S. Army Information Systems Security & Media Sanitization Method

AR 380-19 — Information Systems Security was a U.S. Army regulation establishing information-systems security policy for protecting classified and unclassified-sensitive information. The 27 February 1998 version included specific requirements and procedures for clearing, sanitizing, declassifying, releasing and destroying computer components and magnetic storage media.
Its media-sanitization provisions are particularly relevant to historical Army data-erasure workflows because the regulation addressed overwriting, degaussing, sanitizing/purging and destruction according to media type and security requirements.
Data Sanitization Pro (DSP) provides a dedicated AR 380-19 Army Sanitization Method through the DSP Sanitization Engine, allowing organizations maintaining this historical methodology to execute, verify and document the configured sanitization operation.
AR 380-19 was an Army Information Systems Security regulation, rather than a standalone disk-wiping algorithm.
The regulation established an Army information-systems security framework covering areas such as:
The 1998 regulation specifically included procedures for computer components and magnetic media that were no longer usable, required transfer or needed to be released from control.
AR 380-19 should therefore be represented accurately as a historical U.S. Army security regulation containing media-sanitization requirements and procedures.
It should not be marketed as:
One of the important sections of AR 380-19 addressed:
The regulation explicitly distinguished these activities.
Clearing was defined as eradicating data before reuse where the subsequent environment provided an acceptable level of protection for the previously stored information.
Sanitizing, also described as purging, was intended for reuse in an environment that did not provide an acceptable level of protection for the previous data.
Destruction physically damages the media so that it is no longer usable as storage media and the data cannot be retrieved through a known method.
Declassification was treated as a separate administrative determination, rather than simply another name for wiping data.
This distinction is important when describing AR 380-19 on a modern data-erasure platform.
The regulation's Appendix E/F provisions described overwriting as a software process that replaces previously stored information on magnetic storage media with predetermined meaningless data.
For magnetic disks, the specified preferred overwrite procedure was:
The regulation also required the overwrite operation to be verified by the ISSM or designee.
This is an important technical distinction:
AR 380-19 should not be represented as a generic "DoD 7-pass" or "Army 7-pass" algorithm.
The historical Army procedure documented in the 1998 regulation specified a three-pass magnetic-disk overwrite consisting of random, specified and complementary values.
DSP provides the AR 380-19 methodology as a dedicated option within the DSP Sanitization Engine.
The operator selects:
from the available sanitization methods.
DSP identifies the selected storage device and records available information such as:
DSP can provide available device-health information, including:
For a compatible magnetic-disk workflow, the configured AR 380-19 overwrite process is executed through the:
The process follows the selected methodology rather than being treated as ordinary file deletion.
DSP can display:
The completed overwrite/sanitization operation is verified according to the configured DSP verification workflow.
DSP generates an audit-ready sanitization certificate documenting the actual operation performed.
The historical magnetic-disk overwrite sequence can be represented as:
This differs from other historical sanitization methodologies.
| Method | Common Historical Process |
|---|---|
| AR 380-19 | Random → Specified → Complement |
| Schneier | 7-pass methodology |
| Pfitzner | 33 random-data passes |
| Gutmann | 35-pass sequence |
| DoD 5220.22-M | Historical multi-pass methodology |
| NIST SP 800-88 Rev. 2 | Technology-appropriate Clear/Purge/Destroy framework |
The number of passes should not be interpreted as a universal measure of modern sanitization effectiveness.
AR 380-19 specifically required verification of the overwrite procedure by the Information Systems Security Manager (ISSM) or designee.
This makes verification an important part of the historical methodology.
DSP translates this operational concept into a software workflow:
DSP can record:
AR 380-19 did not treat overwriting as the only possible sanitization mechanism.
The regulation also described degaussing for magnetic media.
Degaussing uses a reverse magnetic field to reduce the magnetic flux of the storage medium. The regulation required the coercivity of the media to be determined before selecting an appropriate degausser.
The regulation identified three historical magnetic-media categories based on coercivity and specified corresponding degaussing requirements.
Therefore, AR 380-19 should be understood as a broader media-security and sanitization framework, rather than simply a three-pass wiping algorithm.
The historical regulation included stronger requirements for certain categories of information.
For example, its Appendix E states that media that had contained SCI, other intelligence information or Restricted Data could not be sanitized by overwriting under those procedures and instead required degaussing before release.
It also specified that media that had ever contained cryptographic material could not be sanitized under those procedures and had to be destroyed.
This illustrates an important principle:
The sanitization method depended on the information handled by the media, not simply on the physical storage device.
The media procedures were heavily oriented toward magnetic storage technologies, including:
The regulation's table provided different procedures depending on media type and degaussing category.
For non-removable and removable hard disks, the historical procedures included:
The regulation explicitly recognized that overwriting effectiveness could be reduced by factors including:
This is particularly relevant to professional data-erasure software.
A software process reporting completion does not automatically establish that every required storage location was successfully overwritten.
DSP can therefore combine:
DEVICE ASSESSMENT+ERROR MONITORING+SANITIZATION+VERIFICATION
to provide a more complete operational record.
AR 380-19 was written around an earlier generation of storage technology and its sanitization procedures should not automatically be applied to modern SSD or NVMe architecture.
Modern flash storage may use:
Host-level overwrite operations may therefore fail to address every physical location that previously contained data.
Current NIST SP 800-88 Rev. 2 specifically addresses this limitation and explains why conventional overwriting may not sanitize all previous data on certain flash-based media.
Therefore:
AR 380-19 should be treated as a historical methodology for applicable legacy workflows, not as a universal SSD/NVMe sanitization technique.
For modern flash storage, the appropriate device-specific Clear or Purge technique should be evaluated.
| Feature | AR 380-19 | NIST SP 800-88 Rev. 2 |
|---|---|---|
| Origin | U.S. Army | NIST |
| Nature | Army information-systems security regulation | Media-sanitization guidance |
| Historical Focus | Classified/sensitive information & system security | Modern media sanitization |
| Historical Overwrite | 3-pass magnetic-disk process | Technology-dependent |
| Degaussing | ✓ Yes | Technology/use-case dependent |
| Current NIST Publication | No | Current |
| SSD/NVMe Guidance | Historical technology context | Modern technology-aware approach |
| DSP Method | Dedicated method | Dedicated methods |
| Audit-Ready DSP Certificate | ✓ Yes | ✓ Yes |
NIST SP 800-88 Rev. 2 is the current NIST media-sanitization publication and superseded Rev. 1 in September 2025.
These two historical U.S. government references are sometimes grouped together in commercial wiping software, but they are not the same methodology.
| Feature | AR 380-19 | DoD 5220.22-M |
|---|---|---|
| Organization | U.S. Army | U.S. Department of Defense |
| Primary Scope | Army information-systems security | Historical NISPOM/security policy |
| Media Procedures | ✓ Yes | ✓ Yes |
| Historical Magnetic Overwrite | Random → specified → complement | Different historical profile |
| Degaussing | ✓ Yes | Historical use |
| Current NIST Standard | No | No |
| DSP Implementation | Dedicated method | Dedicated method |
| Audit-Ready Certificate | ✓ Yes | ✓ Yes |
The AR 380-19 method should therefore not be marketed as simply another name for DoD 5220.22-M.
DSP can provide multiple historical sanitization methodologies for organizations maintaining legacy procedures.
| Method | Historical Association | Common Process |
|---|---|---|
| AR 380-19 | U.S. Army | Random → Specified → Complement |
| AFSSI-5020 | U.S. Air Force | Method-specific |
| DoD 5220.22-M | U.S. DoD | Historical multi-pass |
| Schneier | Bruce Schneier | 7-pass |
| Pfitzner | Roy Pfitzner | 33-pass |
| Gutmann | Peter Gutmann | 35-pass |
Each methodology should be selected based on the applicable organizational requirement and storage technology.
DSP can generate an audit-ready certificate documenting the sanitization operation actually performed.
The DSP certificate documents the actual sanitization operation performed by the software.
It is not certification issued by the U.S. Army, Department of Defense or NIST.
AR 380-19 included procedures for the release of systems and components.
The historical regulation required inspection to ensure that media, including internal disks, had been removed or sanitized and required a record of the sanitization procedure and recipient of released equipment.
This creates a useful conceptual connection with modern ITAD workflows:
DSP's audit-ready reporting can provide the software-side documentation needed to support this type of controlled asset-release process.
DSP can support offline sanitization workflows for environments where continuous internet connectivity is restricted.
This can be useful for:
The selected sanitization method can be executed locally while maintaining a local operational record.
DSP can support professional multi-device sanitization according to the configured licensing and available hardware.
Typical applications include:
Each target device can have its own sanitization and verification record.
AR 380-19 can be relevant where an organization maintains a legacy Army information-security or media-sanitization procedure and specifically requires the historical methodology.
For new sanitization programs, the decision should not be based solely on the Army association or historical pass count.
A modern sanitization decision should consider:
DATA SENSITIVITY+STORAGE TECHNOLOGY+DEVICE CONDITION+SANITIZATION OBJECTIVE+VERIFICATION+VALIDATION
For modern SSD, NVMe and flash media, technology-specific sanitization methods should be evaluated rather than assuming that a historical magnetic-disk overwrite procedure provides equivalent coverage.
DSP provides a dedicated implementation for organizations maintaining the historical Army methodology.
The configured magnetic-disk overwrite process can follow the documented random → specified → complement sequence.
DSP records the sanitization and verification outcome.
Identify the device and review available health information.
Potential write failures and bad-sector conditions can be identified and reported.
Generate documentation of the operation performed.
Suitable for restricted and air-gapped environments.
Designed for professional storage sanitization and asset-retirement workflows.
Data Sanitization Pro provides a dedicated library of established, historical and technology-specific sanitization methodologies.
For organizations maintaining AR 380-19-based workflows, DSP provides:
The selected method is executed through the DSP Sanitization Engine, followed by verification and audit-ready documentation.
Method selection should be based on the applicable organizational requirement, storage technology and intended sanitization objective.
AR 380-19 was a U.S. Army **Information Systems Security** regulation covering protection of classified and unclassified-sensitive information and including procedures for clearing, sanitizing and releasing computer components and storage media.
The 1998 regulation specified a preferred magnetic-disk overwrite procedure of three passes: a random character, a specified character and the complement of that specified character. It also required verification.
No. It is a historical Army regulation. Current NIST media-sanitization guidance is **NIST SP 800-88 Rev. 2**.
No. They are different historical U.S. government security references.
Yes. Its media procedures included degaussing and specified that the degausser capability had to match the coercivity of the magnetic media.
Yes. The regulation explicitly recognized that inability to overwrite bad sectors or tracks could reduce the effectiveness of overwriting.
The historical procedure was designed around storage technologies of its era, particularly magnetic media. It should not automatically be treated as sufficient for modern SSD/NVMe storage.
Yes. DSP can generate an audit-ready certificate documenting the sanitization method executed, device information, verification result and relevant audit metadata.
No. It documents the operation performed by DSP and is not issued by the U.S. Army.
Data Sanitization Pro runs all 25 standards offline and verifies the result.