Pass 1 — Zero Pattern
The first pass writes a zero-value pattern:
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
Secure Multi-Pass Data Erasure Based On The Historical UK HMG IS5 Enhanced Method

HMG IS5 Enhanced is a historical UK secure sanitization methodology associated with HMG Information Assurance Standard No. 5 (IS5) — SecureSanitisation, formerly issued under the UK's CESG information-assurance framework.
The Enhanced method is commonly implemented as a three-pass overwrite process, using:
Data Sanitization Pro (DSP) provides a dedicated HMG IS5 Enhanced Sanitization Method through the DSP Sanitization Engine, enabling organizations to execute the configured method, verify the result, document the operation and generate an audit-ready sanitization certificate.
Important: HMG IS5 is a historical UK methodology. It should not be represented as a current NCSC-issued certification or as a current universal UK Government requirement. UK guidance has evolved toward risk-based secure sanitisation practices.
HMG IS5 Enhanced was designed as a stronger multi-pass sanitization profile than the Baseline method.
In commonly implemented software profiles, the Enhanced method performs three overwrite passes:
| Pass | Operation |
|---|---|
| Pass 1 | Write 0x00 across addressable sectors |
| Pass 2 | Write 0xFF across addressable sectors |
| Pass 3 | Write random data across addressable sectors |
| Verification | Verify the completed sanitization operation |
This three-pass representation is documented in Common Criteria security-target material for certified erasure products.
The purpose is to replace previously stored information with multiple defined patterns before completing a final verification stage.
DSP implements HMG IS5 Enhanced as a dedicated sanitization method, rather than presenting it as a generic multi-pass wipe.
SELECT HMG IS5 ENHANCED ↓ IDENTIFY DEVICE ↓ ASSESS STORAGE MEDIA ↓ DSP SANITIZATION ENGINE ↓ PASS 1 — 0x00 ↓ PASS 2 — 0xFF ↓ PASS 3 — RANDOM DATA ↓ VERIFY RESULT ↓ DOCUMENT OPERATION ↓ AUDIT-READY SANITIZATION CERTIFICATE
The selected method, device identity, execution status and verification information can be recorded as part of the sanitization report.
The first pass writes a zero-value pattern:
across the addressable storage area targeted by the sanitization operation.
This replaces existing logical data with a deterministic binary pattern.
The second pass writes:
across the target area.
This replaces the previous zero pattern with its complementary byte value.
The third pass writes random data across the target area.
The final pass removes the predictable pattern left by the previous two operations and is followed by verification.
DSP verifies the completed sanitization process and records the verification outcome.
Where required by organizational procedures, the resulting report can provide evidence of:
HMG IS5 Enhanced is primarily encountered as a software-based multi-pass data wiping methodology.
It can be relevant where an organization has specifically selected or contractually requires the historical HMG IS5 Enhanced profile.
Typical use cases include:
A three-pass overwrite should not automatically be treated as equivalent to every modern media-sanitization requirement. The appropriate sanitization technique depends on the storage technology, data sensitivity, device condition and intended disposition.
HMG IS5 Enhanced is particularly associated with traditional magnetic storage and addressable-sector overwrite operations.
For conventional HDDs, DSP can:
DSP can provide operational information such as:
Drive Model Serial Number Capacity Interface Temperature Power-On Hours Health Status Bad-Sector Information Sanitization Progress Write Rate Elapsed Time Estimated Completion Verification Result
This provides additional device-level context around the actual sanitization operation.
Modern SSD and NVMe storage requires additional consideration.
Unlike traditional magnetic HDDs, flash storage uses technologies such as:
Consequently, repeatedly overwriting logical sectors through a normal interface does not necessarily guarantee that every historical physical flash location has been overwritten.
For this reason, HMG IS5 Enhanced should not be treated as a universal physical sanitization technique for every SSD or NVMe device.
DSP can identify the storage technology and provide the applicable sanitization workflow. Where a media-specific command or stronger sanitization technique is appropriate organizations should select the method according to their security policy and applicable modern guidance.
This distinction is particularly important when comparing historical multi-pass wiping methods with modern storage sanitization approaches such as NIST SP 800-88 Rev. 2 and IEEE 2883.
| Feature | HMG IS5 Baseline | HMG IS5 Enhanced |
|---|---|---|
| Historical UK Methodology | ✓ Yes | ✓ Yes |
| Typical Software Implementation | Single pass | Three passes |
| Pass 1 | Implementation-dependent | 0x00 |
| Pass 2 | — | 0xFF |
| Pass 3 | — | Random data |
| Verification | ✓ Yes | ✓ Yes |
| Primary Historical Use | Secure sanitization | Enhanced multi-pass sanitization |
| Modern SSD Suitability | Media-dependent | Media-dependent |
| DSP Dedicated Method | ✓ Yes | ✓ Yes |
The Enhanced profile therefore represents a multi-pass historical wiping methodology, rather than simply a higher number of repeated identical writes.
HMG IS5 Enhanced and the historical DoD 5220.22-M three-pass method are frequently grouped together because both are commonly represented by three-pass overwrite profiles.
However, they should not automatically be described as the same standard.
A commonly documented HMG IS5 Enhanced profile uses:
Historical DoD 5220.22-M software implementations are also commonly represented using a three-pass sequence involving zeroes, ones/complementary data and random data with verification.
DSP maintains them as separate sanitization methods, allowing the operator to select the methodology actually required by the organization's policy or workflow.
Historical multi-pass overwrite methods remain relevant when an organization specifically requires them, but modern storage sanitization has evolved.
| Method | General Approach |
|---|---|
| HMG IS5 Enhanced | Historical three-pass overwrite profile |
| HMG IS5 Baseline | Historical baseline sanitization profile |
| NIST SP 800-88 Rev. 2 Clear | Risk-based logical sanitization |
| NIST SP 800-88 Rev. 2 Purge | Stronger logical/physical sanitization |
| IEEE 2883-2022 | Technology-specific storage sanitization |
| Physical Destruction | Media rendered unusable |
The appropriate method should be selected based on data sensitivity, storage technology, device condition, reuse requirements and organizational policy, rather than simply choosing the method with the greatest number of overwrite passes.
Sanitization is more than starting a wipe process.
DSP records the execution and verification outcome of the selected HMG IS5 Enhanced method.
Depending on the configured workflow, the report can document:
A successful sanitization process depends on the storage area being accessible to the selected technique.
DSP can identify and report conditions such as:
This is important for asset disposition because a drive with inaccessible sectors may require a different sanitization decision rather than simply being marked as successfully wiped.
IT Asset Disposition operations often process large numbers of retired computers and storage devices.
DSP can support ITAD workflows requiring:
This provides a structured workflow from device intake to sanitization evidence.
DSP can support offline sanitization workflows where devices cannot be connected to external cloud services.
This can be useful for:
The sanitization process can be executed locally while maintaining the relevant device, execution and verification information required for reporting.
After the sanitization process, DSP can generate an audit-ready sanitization certificate documenting the operation performed by the software.
The certificate can include:
HMG IS5 Enhanced Device Identity Serial Number Capacity Sanitization Execution Pass Information Verification Result Operator Information System Information Date & Time Audit Metadata
The DSP certificate is evidence of the sanitization operation performed by DSP.
It is not a certificate issued by NCSC, CESG, the UK Government or another standards authority and it should not be presented as external HMG certification of DSP.
The distinction is important when preparing compliance, procurement or ITAD documentation.
HMG IS5 is a historical/former UK secure-sanitisationframework. Current UK government and NCSC material refers to modern secure-sanitisation guidance rather than treating IS5 as a universal current wiping requirement. UK government material also shows that HMG IS5 can still appear in specific contractual or departmental requirements.
The NCSC's sanitisation assurance landscape has also evolved; its former CAS-S scheme closed on 5 January 2026, with new assurance arrangements introduced through Cyber Resilience Test Facilities.
Therefore organizations should distinguish between:
Historical HMG IS5 Enhanced methodology and Current UK secure-sanitisationrequirements
when defining their sanitization policy.
DSP provides a dedicated implementation of the HMG IS5 Enhanced methodology through its DSP Sanitization Engine.
IDENTIFY Identify the storage device.
CLASSIFY Determine media type and device characteristics.
ASSESS Check device condition, accessibility and relevant storage information.
SELECT Select HMG IS5 Enhanced.
EXECUTE Run the configured three-pass sanitization process.
VERIFY Verify the sanitization result.
VALIDATE Review the result and determine whether the device meets the organization's acceptance criteria.
DOCUMENT Record the operation and verification evidence.
CERTIFY Generate the audit-ready DSP sanitization certificate.
HMG IS5 Enhanced is one of the sanitization methods available through DSP.
Organizations can use the DSP Sanitization Engine to select the methodology required for their specific workflow rather than maintaining separate wiping applications for different standards.
Supported methodology profiles include modern and historical approaches such as:
Each method is executed as its own selectable DSP sanitization profile, with method-specific processing, verification and reporting.
HMG IS5 Enhanced is available as a distinct sanitization method within DSP.
The configured Enhanced profile performs the defined multi-pass overwrite process.
DSP verifies the sanitization operation and records the result.
Device identity, health and storage information can be captured alongside the sanitization process.
Potentially inaccessible or problematic storage areas can be identified and documented.
Organizations can sanitize multiple supported devices according to their operational workflow.
Suitable for environments where sanitization must be performed without an internet connection.
Generate documentation containing device, sanitization, verification and operator information.
HMG IS5 is a historical/former UK secure-sanitisation framework. Current UK guidance has evolved, although HMG IS5 can still appear in specific contractual or departmental requirements.
The commonly implemented software profile uses **three passes**: followed by verification.
No. They are separate historical methodologies, even though commonly documented implementations use similar three-pass concepts.
Not necessarily. SSDs and NVMe devices use flash-management technologies that can make traditional repeated logical overwriting unsuitable as a universal sanitization strategy.
Yes. DSP can generate an **audit-ready sanitization certificate** documenting the HMG IS5 Enhanced operation performed by DSP.
No. It documents the sanitization operation performed by DSP and should not be represented as NCSC, CESG or UK Government certification.
Yes. It can be selected where the organization or contractual requirement specifically calls for the historical HMG IS5 Enhanced methodology.
Data Sanitization Pro runs all 25 standards offline and verifies the result.