Identify
DSP identifies the selected storage device and records available:
- Manufacturer
- Model
- Serial number
- Capacity
- Interface
- Device type
- Storage technology
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
British HMG IS5 Baseline Data Sanitization Method

HMG IS5 Baseline is a historically significant UK government secure-sanitisation methodology associated with HMG Information Assurance Standard No. 5 (IS5) — SecureSanitisation.
The methodology was developed under the former UK government information-assurance framework and is widely referenced in secure data-erasure software for controlled overwriting and verification of storage media.
Today, IS5 should be treated as a legacy UK governmentsanitisationmethodology. UK government procurement and guidance documents explicitly describe secure sanitisation as the treatment of storage media to reduce the likelihood of data retrieval and reconstruction, while noting that IS5 was the former framework and that current guidance is provided by the National Cyber Security Centre (NCSC).
Data Sanitization Pro (DSP) provides a dedicated HMG IS5 Baseline Sanitization Method through the DSP Sanitization Engine, with controlled execution, verification, device monitoring and audit-ready certification.
HMG IS5 refers to HMG Information Assurance Standard No. 5 — SecureSanitisation, a former UK government information-assurance standard for secure treatment of information stored on media.
The underlying objective of secure sanitisation is to reduce the likelihood that previously stored information can be retrieved and reconstructed after the media is released, reused or otherwise disposed of. UK government documentation continues to use this definition of secure sanitisation while identifying IS5 as the former standard and directing users to current NCSC guidance.
The Baseline profile is the simpler of the commonly referenced HMG IS5 overwrite profiles.
It is generally represented as:
The commonly implemented software profile uses a single overwrite pass, followed by verification. Different software products may document the historical pass value differently, which is why a professional implementation should identify the actual sanitization operation executed rather than claiming that every IS5 Baseline implementation is identical.
The DSP implementation follows a controlled sanitization workflow:
DSP identifies the selected storage device and records available:
Available device-health and media information can be reviewed before sanitization.
The DSP Sanitization Engine executes the configured HMG IS5 Baseline overwrite profile.
DSP verifies the result and records the outcome.
The operation, device and verification information are captured for audit purposes.
DSP generates an audit-ready sanitization certificate documenting the operation actually performed.
The Baseline profile is commonly represented as a single-pass overwrite followed by verification.
A simplified process is:
The purpose is to replace addressable information with the selected overwrite value and then confirm the sanitization result.
Some technical references describe HMG IS5 Baseline as a zero overwrite, while others use a random-value implementation. This reflects differences in software implementations and historical descriptions.
For DSP, the important audit principle is:
The certificate should identify the actual sanitization profile executed by the DSP Sanitization Engine.
This avoids treating a generic software label as proof of an operation that may not have actually been performed.
DSP provides HMG IS5 Baseline as a dedicated method within the DSP Sanitization Engine.
The operator does not need to create a custom overwrite sequence.
Select the target HDD or other supported storage device.
DSP executes the configured Baseline overwrite process.
The resulting storage state is checked according to the configured verification process.
DSP creates the corresponding audit-ready sanitization certificate.
During execution, DSP can provide visibility into:
This is particularly useful for professional ITAD, enterprise and bulk media sanitization operations where every device needs traceable processing information.
HMG IS5 Baseline is most naturally associated with software-based sanitization of rewriteable storage media, particularly traditional HDDs.
For supported HDDs, DSP can record:
This supports controlled workflows for:
Modern SSD and NVMe devices require additional technical consideration.
Flash storage incorporates:
As a result, repeatedly writing to logical sectors through a normal interface does not necessarily mean that every historical physical NAND location has been overwritten.
Therefore, HMG IS5 Baseline should not automatically be treated as a universal physical sanitization technique for SSD or NVMe media.
For modern solid-state storage organizations should select a sanitization technique appropriate to:
Where available, device-native sanitization capabilities may be more appropriate than conventional logical overwriting.
Secure sanitization is fundamentally different from ordinary deletion.
| Operation | General Result |
|---|---|
| File Deletion | Removes filesystem references |
| Quick Format | Recreates filesystem structures |
| Factory Reset | Reinitializes data according to device implementation |
| HMG IS5 Baseline | Executes a defined single-pass sanitization profile with verification |
| Physical Destruction | Makes the storage medium unusable |
Deleting files or formatting a disk does not by itself establish that previously stored information has been securely sanitized.
A professional data-erasure process should have a defined method, controlled execution and documented verification.
Verification is a critical component of a professional sanitization workflow.
DSP records the result of the sanitization operation and verification stage.
The audit record can include:
This creates evidence connecting the physical device to the sanitization operation.
A storage device's physical condition can affect successful sanitization.
DSP can provide available device-health information including:
If a device contains inaccessible sectors or reports significant errors, the result should identify those conditions.
A completed software operation should not automatically be interpreted as proof that inaccessible physical areas were successfully overwritten.
HMG IS5 Baseline can be used as a selectable sanitization profile within structured IT Asset Disposition (ITAD) workflows when a customer, contract or organizational policy specifically requires the methodology.
DSP creates a traceable chain:
This allows an ITAD operator to associate each physical storage device with its sanitization result.
Typical applications include:
Sanitize retired employee computers and storage devices before reuse or resale.
Process supported storage media before controlled redeployment.
Sanitize decommissioned storage devices.
Document sanitization before downstream asset processing.
Maintain device-level evidence for retired storage assets.
DSP generates an audit-ready sanitization certificate documenting the HMG IS5 Baseline operation actually performed.
The certificate documents the operation performed by DSP.
It is not an NCSC-issued, CESG-issued or UK Government-issued certification.
The two commonly referenced IS5 profiles should not be treated as identical.
| Feature | HMG IS5 Baseline | HMG IS5 Enhanced |
|---|---|---|
| Historical UK IS5 Profile | ✓ Yes | ✓ Yes |
| Typical Software Implementation | Single overwrite | Three overwrite passes |
| Common Pattern Description | Single selected value | 0x00 → 0xFF → random |
| Verification | ✓ Yes | ✓ Yes |
| Processing Time | Lower | Higher |
| Primary Concept | Baseline overwrite | Extended overwrite |
Commercial and technical references commonly describe the Enhanced profile as a three-pass sequence using zero, one/complement and random data, followed by verification.
The pass count should not, however, be interpreted as a universal measure of sanitization strength across modern storage technologies.
HMG IS5 and current NIST media-sanitization guidance represent different generations of sanitization practice.
A historical UK government overwrite profile commonly implemented as a single software overwrite followed by verification.
Current NIST media-sanitization guidance that distinguishes Clear, Purge and Destroy and emphasizes selecting techniques appropriate to the storage technology and information-sensitivity requirements.
For modern SSD and NVMe devices organizations should not assume that a historical single-pass overwrite provides the same sanitization outcome as an appropriate device-specific Clear or Purge technique.
This distinction is important for organizations using the HMG IS5 name today.
UK government documentation identifies HMG IA Standard No. 5 — SecureSanitisation as a former standard and directs users toward current NCSC guidance for secure sanitisation of storage media.
At the same time, current UK government procurement documentation continues to reference IS5 where contractual or departmental requirements specifically call for it. For example, an August 2026 UK government FOI response states that end-of-life hardware/media containing data must be handled in accordance with HMG Information Assurance Standard No. 5 and that relevant certification and a Certified Data Security Report may be required when an external provider performs the service.
Therefore, the correct modern positioning is:
rather than presenting HMG IS5 Baseline as the current universal UK sanitization standard.
DSP supports offline sanitization workflows for environments where internet connectivity is restricted or unavailable.
This can be valuable for:
The sanitization operation can be executed locally while the resulting certificate and audit information are retained for reporting.
Enterprise and ITAD operations may need to process many storage devices.
DSP provides structured device-level processing with visibility into:
The operational sequence is:
This allows organizations to standardize the processing of supported storage media.
DSP provides a dedicated HMG IS5 Baseline sanitization method.
The selected profile is executed through the DSP Sanitization Engine.
Device information is recorded for traceability.
Progress, rate, elapsed time and status can be monitored.
The sanitization result is verified and documented.
Available SMART and media-health information can be assessed.
Bad sectors and device errors can be identified.
DSP generates an audit-ready sanitization certificate.
Suitable for disconnected and restricted environments.
Designed for structured storage-device processing.
HMG IS5 Baseline remains a recognizable UK secure-sanitization methodology, particularly where historical requirements, customer contracts or organizational procedures explicitly specify it.
With Data Sanitization Pro, the selected HMG IS5 Baseline profile is executed through the DSP Sanitization Engine, monitored during processing, verified after execution and documented through an audit-ready sanitization certificate.
For current deployments organizations should also evaluate applicable NCSC guidance and current media-specific sanitization practices, particularly for SSD, NVMe and other modern storage architectures.
HMG IS5 Baseline is a historical UK government secure-sanitization profile associated with HMG Information Assurance Standard No. 5.
IS5 is a **former** UK government standard. Current UK government material points to NCSC secure-sanitization guidance, although IS5 can still appear in current contractual or departmental requirements.
The commonly implemented Baseline profile uses **one overwrite pass followed by verification**. Technical references differ on the exact value used for the overwrite, so the actual DSP implementation should be documented in the sanitization certificate.
No. Baseline is commonly implemented as a single overwrite, while Enhanced is commonly represented as a three-pass overwrite profile followed by verification.
It is primarily associated with software-based sanitization of rewriteable storage media and is commonly used for HDD wiping workflows.
A conventional logical overwrite should not automatically be treated as complete physical SSD sanitization because of flash translation, wear leveling, spare blocks and over-provisioning.
Yes. DSP provides a dedicated HMG IS5 Baseline Sanitization Method through the DSP Sanitization Engine.
Yes. DSP generates an audit-ready certificate documenting the actual sanitization operation performed by DSP.
No. The certificate is generated by DSP and documents the operation performed by the software. It is not an NCSC, CESG or UK Government certification.
Data Sanitization Pro runs all 25 standards offline and verifies the result.