CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standard 21 Of 25 · Government And Defence

AR 380-19 Army — Secure Data Erasure & Media Sanitization

Historical U.S. Army Information Systems Security & Media Sanitization Method

United States3 PassesVerification Required
Army IT equipment being sanitized to AR 380-19

At A Glance

Published By
US Army
Reference
Army Regulation 380-19, Information Systems Security
Region
United States
Passes
3
Verification
Required By The Standard, Locked On
Relative Run Time
4× a single pass

What The Software Writes

  1. Pass 1 Random data
  2. Pass 2 Fixed pattern 0x55
  3. Pass 3 Fixed pattern 0xAA
  4. Verify Required by the standard. Every sector is read back and compared.
  5. Certify Signed certificate with device, method, result and operator

AR 380-19 — Information Systems Security was a U.S. Army regulation establishing information-systems security policy for protecting classified and unclassified-sensitive information. The 27 February 1998 version included specific requirements and procedures for clearing, sanitizing, declassifying, releasing and destroying computer components and magnetic storage media.

Its media-sanitization provisions are particularly relevant to historical Army data-erasure workflows because the regulation addressed overwriting, degaussing, sanitizing/purging and destruction according to media type and security requirements.

Data Sanitization Pro (DSP) provides a dedicated AR 380-19 Army Sanitization Method through the DSP Sanitization Engine, allowing organizations maintaining this historical methodology to execute, verify and document the configured sanitization operation.

  1. 01Select Method
  2. 02Select Device
  3. 03DSP Sanitization Engine
  4. 04Execute
  5. 05Verify
  6. 06Document
  7. 07Certify
01

What Is AR 380-19?

AR 380-19 was an Army Information Systems Security regulation, rather than a standalone disk-wiping algorithm.

The regulation established an Army information-systems security framework covering areas such as:

  • Computer Security
  • Communications Security
  • Electronic Security
  • Risk Management
  • System Accreditation
  • Protection Of Classified Information
  • Protection Of Sensitive Unclassified Information
  • Media Clearing And Sanitization
  • Equipment Release And Disposal

The 1998 regulation specifically included procedures for computer components and magnetic media that were no longer usable, required transfer or needed to be released from control.

02

Important Classification

AR 380-19 should therefore be represented accurately as a historical U.S. Army security regulation containing media-sanitization requirements and procedures.

It should not be marketed as:

  • A Current NIST Media-Sanitization Standard
  • A Current IEEE Storage-Sanitization Standard
  • A Current Universal U.S. Army Disk-Wiping Standard
  • A Government Certification Issued By DSP
  • An External Certification Issued By The U.S. Army
03

AR 380-19 Media Sanitization

One of the important sections of AR 380-19 addressed:

  1. 01Clearing
  2. 02Sanitizing
  3. 03Declassification
  4. 04Release
  5. 05Destruction

The regulation explicitly distinguished these activities.

04

Clearing

Clearing was defined as eradicating data before reuse where the subsequent environment provided an acceptable level of protection for the previously stored information.

Sanitizing / Purging

Sanitizing, also described as purging, was intended for reuse in an environment that did not provide an acceptable level of protection for the previous data.

Destroying

Destruction physically damages the media so that it is no longer usable as storage media and the data cannot be retrieved through a known method.

Declassification

Declassification was treated as a separate administrative determination, rather than simply another name for wiping data.

This distinction is important when describing AR 380-19 on a modern data-erasure platform.

AR 380-19 Overwriting Procedure

The regulation's Appendix E/F provisions described overwriting as a software process that replaces previously stored information on magnetic storage media with predetermined meaningless data.

For magnetic disks, the specified preferred overwrite procedure was:

05

Three-Pass Overwrite

Pass 1Random Character
Pass 2Specified Character
Pass 3Complement Of Specified Character

The regulation also required the overwrite operation to be verified by the ISSM or designee.

This is an important technical distinction:

AR 380-19 should not be represented as a generic "DoD 7-pass" or "Army 7-pass" algorithm.

The historical Army procedure documented in the 1998 regulation specified a three-pass magnetic-disk overwrite consisting of random, specified and complementary values.

06

AR 380-19 With Data Sanitization Pro

DSP provides the AR 380-19 methodology as a dedicated option within the DSP Sanitization Engine.

Select AR 380-19

The operator selects:

AR 380-19 Army

from the available sanitization methods.

Identify The Device

DSP identifies the selected storage device and records available information such as:

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Media type
  • Firmware
  • Device status

Assess The Device

DSP can provide available device-health information, including:

  • SMART information
  • Temperature
  • Power-on hours
  • Device health
  • Read/write errors
  • Logical bad sectors
  • Physical bad-sector indicators

Execute The Selected Method

For a compatible magnetic-disk workflow, the configured AR 380-19 overwrite process is executed through the:

DSP Sanitization Engine

The process follows the selected methodology rather than being treated as ordinary file deletion.

Monitor

DSP can display:

  • Current pass
  • Overall progress
  • Processing rate
  • Elapsed time
  • Estimated remaining time
  • Device status
  • Errors
  • Events
  • Verification state

Verify

The completed overwrite/sanitization operation is verified according to the configured DSP verification workflow.

Certify

DSP generates an audit-ready sanitization certificate documenting the actual operation performed.

07

AR 380-19 Three-Pass Disk Wiping

The historical magnetic-disk overwrite sequence can be represented as:

  1. 01Random
  2. 02Specified Character
  3. 03Complement

This differs from other historical sanitization methodologies.

MethodCommon Historical Process
AR 380-19Random → Specified → Complement
Schneier7-pass methodology
Pfitzner33 random-data passes
Gutmann35-pass sequence
DoD 5220.22-MHistorical multi-pass methodology
NIST SP 800-88 Rev. 2Technology-appropriate Clear/Purge/Destroy framework

The number of passes should not be interpreted as a universal measure of modern sanitization effectiveness.

08

Verification Was Part Of The Historical Procedure

AR 380-19 specifically required verification of the overwrite procedure by the Information Systems Security Manager (ISSM) or designee.

This makes verification an important part of the historical methodology.

DSP translates this operational concept into a software workflow:

  1. 01Execute
  2. 02Verify
  3. 03Record Result

DSP can record:

  • Sanitization Method
  • Device Information
  • Operation Status
  • Pass Status
  • Errors
  • Verification Result
  • Operator/system Information
  • Date And Time
09

AR 380-19 And Degaussing

AR 380-19 did not treat overwriting as the only possible sanitization mechanism.

The regulation also described degaussing for magnetic media.

Degaussing uses a reverse magnetic field to reduce the magnetic flux of the storage medium. The regulation required the coercivity of the media to be determined before selecting an appropriate degausser.

The regulation identified three historical magnetic-media categories based on coercivity and specified corresponding degaussing requirements.

Therefore, AR 380-19 should be understood as a broader media-security and sanitization framework, rather than simply a three-pass wiping algorithm.

10

AR 380-19 And Sensitive Media

The historical regulation included stronger requirements for certain categories of information.

For example, its Appendix E states that media that had contained SCI, other intelligence information or Restricted Data could not be sanitized by overwriting under those procedures and instead required degaussing before release.

It also specified that media that had ever contained cryptographic material could not be sanitized under those procedures and had to be destroyed.

This illustrates an important principle:

The sanitization method depended on the information handled by the media, not simply on the physical storage device.

11

AR 380-19 And Magnetic Storage

The media procedures were heavily oriented toward magnetic storage technologies, including:

  • Magnetic Tape
  • Magnetic Disk Packs
  • Magnetic Disks
  • Removable Hard Disks
  • Non-Removable Hard Disks
  • Other Historical Magnetic Media

The regulation's table provided different procedures depending on media type and degaussing category.

For non-removable and removable hard disks, the historical procedures included:

  • Degaussing
  • Or Three-Pass Overwrite
  • Subject To The Applicable Media/security Requirements
12

AR 380-19 And Bad Sectors

The regulation explicitly recognized that overwriting effectiveness could be reduced by factors including:

  • Equipment Failure
  • Read/write-Head Alignment Problems
  • Inability To Overwrite Bad Sectors
  • Inability To Overwrite Bad Tracks
  • Information In Inter-Record Gaps

This is particularly relevant to professional data-erasure software.

A software process reporting completion does not automatically establish that every required storage location was successfully overwritten.

DSP can therefore combine:

DEVICE ASSESSMENT+ERROR MONITORING+SANITIZATION+VERIFICATION

to provide a more complete operational record.

13

AR 380-19 For SSD And NVMe

AR 380-19 was written around an earlier generation of storage technology and its sanitization procedures should not automatically be applied to modern SSD or NVMe architecture.

Modern flash storage may use:

  • Flash Translation Layers
  • Wear Leveling
  • Spare Cells
  • Over-Provisioning
  • Garbage Collection
  • Remapped Physical Locations

Host-level overwrite operations may therefore fail to address every physical location that previously contained data.

Current NIST SP 800-88 Rev. 2 specifically addresses this limitation and explains why conventional overwriting may not sanitize all previous data on certain flash-based media.

Therefore:

AR 380-19 should be treated as a historical methodology for applicable legacy workflows, not as a universal SSD/NVMe sanitization technique.

For modern flash storage, the appropriate device-specific Clear or Purge technique should be evaluated.

14

AR 380-19 vs NIST SP 800-88 Rev. 2

FeatureAR 380-19NIST SP 800-88 Rev. 2
OriginU.S. ArmyNIST
NatureArmy information-systems security regulationMedia-sanitization guidance
Historical FocusClassified/sensitive information & system securityModern media sanitization
Historical Overwrite3-pass magnetic-disk processTechnology-dependent
Degaussing✓ YesTechnology/use-case dependent
Current NIST PublicationNoCurrent
SSD/NVMe GuidanceHistorical technology contextModern technology-aware approach
DSP MethodDedicated methodDedicated methods
Audit-Ready DSP Certificate✓ Yes✓ Yes

NIST SP 800-88 Rev. 2 is the current NIST media-sanitization publication and superseded Rev. 1 in September 2025.

15

AR 380-19 vs DoD 5220.22-M

These two historical U.S. government references are sometimes grouped together in commercial wiping software, but they are not the same methodology.

FeatureAR 380-19DoD 5220.22-M
OrganizationU.S. ArmyU.S. Department of Defense
Primary ScopeArmy information-systems securityHistorical NISPOM/security policy
Media Procedures✓ Yes✓ Yes
Historical Magnetic OverwriteRandom → specified → complementDifferent historical profile
Degaussing✓ YesHistorical use
Current NIST StandardNoNo
DSP ImplementationDedicated methodDedicated method
Audit-Ready Certificate✓ Yes✓ Yes

The AR 380-19 method should therefore not be marketed as simply another name for DoD 5220.22-M.

16

AR 380-19 vs Other Historical Wiping Methods

DSP can provide multiple historical sanitization methodologies for organizations maintaining legacy procedures.

MethodHistorical AssociationCommon Process
AR 380-19U.S. ArmyRandom → Specified → Complement
AFSSI-5020U.S. Air ForceMethod-specific
DoD 5220.22-MU.S. DoDHistorical multi-pass
SchneierBruce Schneier7-pass
PfitznerRoy Pfitzner33-pass
GutmannPeter Gutmann35-pass

Each methodology should be selected based on the applicable organizational requirement and storage technology.

17

Audit-Ready AR 380-19 Sanitization Certificate

DSP can generate an audit-ready certificate documenting the sanitization operation actually performed.

Device Information

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Media type
  • Firmware

Sanitization Information

  • Selected method
  • AR 380-19
  • Configured sanitization process
  • Start time
  • Completion time
  • Duration
  • Sanitization status
  • Verification status

Operator & System

  • Operator
  • Workstation
  • DSP software version
  • System information
  • Execution metadata

Audit Information

  • Case/reference information where configured
  • Date/time
  • Result
  • Verification information
  • Certificate identification

The DSP certificate documents the actual sanitization operation performed by the software.

It is not certification issued by the U.S. Army, Department of Defense or NIST.

18

Release & Documentation

AR 380-19 included procedures for the release of systems and components.

The historical regulation required inspection to ensure that media, including internal disks, had been removed or sanitized and required a record of the sanitization procedure and recipient of released equipment.

This creates a useful conceptual connection with modern ITAD workflows:

  1. 01Sanitize
  2. 02Verify
  3. 03Document
  4. 04Release

DSP's audit-ready reporting can provide the software-side documentation needed to support this type of controlled asset-release process.

19

Offline AR 380-19 Data Erasure

DSP can support offline sanitization workflows for environments where continuous internet connectivity is restricted.

This can be useful for:

  • Government Environments
  • Secure Facilities
  • Enterprise IT
  • ITAD Operations
  • Data Centers
  • Air-Gapped Environments
  • Restricted Networks

The selected sanitization method can be executed locally while maintaining a local operational record.

20

Multi-Device Sanitization

DSP can support professional multi-device sanitization according to the configured licensing and available hardware.

Typical applications include:

  • HDD Batch Sanitization
  • Enterprise Asset Retirement
  • ITAD Processing
  • Storage Refurbishment
  • Data-Center Decommissioning
  • Corporate Equipment Disposal

Each target device can have its own sanitization and verification record.

21

When Should AR 380-19 Be Used?

AR 380-19 can be relevant where an organization maintains a legacy Army information-security or media-sanitization procedure and specifically requires the historical methodology.

For new sanitization programs, the decision should not be based solely on the Army association or historical pass count.

A modern sanitization decision should consider:

DATA SENSITIVITY+STORAGE TECHNOLOGY+DEVICE CONDITION+SANITIZATION OBJECTIVE+VERIFICATION+VALIDATION

For modern SSD, NVMe and flash media, technology-specific sanitization methods should be evaluated rather than assuming that a historical magnetic-disk overwrite procedure provides equivalent coverage.

22

Why Use DSP For AR 380-19?

Dedicated AR 380-19 Method

DSP provides a dedicated implementation for organizations maintaining the historical Army methodology.

Historical Three-Pass Workflow

The configured magnetic-disk overwrite process can follow the documented random → specified → complement sequence.

Verification

DSP records the sanitization and verification outcome.

Device Intelligence

Identify the device and review available health information.

Bad-Sector Awareness

Potential write failures and bad-sector conditions can be identified and reported.

Audit-Ready Reporting

Generate documentation of the operation performed.

Offline Operation

Suitable for restricted and air-gapped environments.

Enterprise & ITAD

Designed for professional storage sanitization and asset-retirement workflows.

23

25 Sanitization Methods In Data Sanitization Pro

Data Sanitization Pro provides a dedicated library of established, historical and technology-specific sanitization methodologies.

For organizations maintaining AR 380-19-based workflows, DSP provides:

AR 380-19 Army Sanitization Method

The selected method is executed through the DSP Sanitization Engine, followed by verification and audit-ready documentation.

Method selection should be based on the applicable organizational requirement, storage technology and intended sanitization objective.

FAQ

US Army Questions

What Is AR 380-19?

AR 380-19 was a U.S. Army **Information Systems Security** regulation covering protection of classified and unclassified-sensitive information and including procedures for clearing, sanitizing and releasing computer components and storage media.

Does AR 380-19 Specify A Three-Pass Overwrite?

The 1998 regulation specified a preferred magnetic-disk overwrite procedure of three passes: a random character, a specified character and the complement of that specified character. It also required verification.

Is AR 380-19 A Current NIST Standard?

No. It is a historical Army regulation. Current NIST media-sanitization guidance is **NIST SP 800-88 Rev. 2**.

Is AR 380-19 The Same As DoD 5220.22-M?

No. They are different historical U.S. government security references.

Did AR 380-19 Include Degaussing?

Yes. Its media procedures included degaussing and specified that the degausser capability had to match the coercivity of the magnetic media.

Did AR 380-19 Address Bad Sectors?

Yes. The regulation explicitly recognized that inability to overwrite bad sectors or tracks could reduce the effectiveness of overwriting.

Can The AR 380-19 Method Be Used On SSDs?

The historical procedure was designed around storage technologies of its era, particularly magnetic media. It should not automatically be treated as sufficient for modern SSD/NVMe storage.

Does DSP Provide An AR 380-19 Certificate?

Yes. DSP can generate an audit-ready certificate documenting the sanitization method executed, device information, verification result and relevant audit metadata.

Is The DSP Certificate An Official Army Certification?

No. It documents the operation performed by DSP and is not issued by the U.S. Army.

AR 380-19 Army — Professional Data Sanitization

Data Sanitization Pro runs all 25 standards offline and verifies the result.