CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standard 07 Of 25 · Modern And Device Aware

ISO/IEC 27040:2024 — Storage Security & Secure Data Sanitization Software

International Storage Security Standard For Data Protection, Sanitization & End-Of-Life Media Management

International1 PassVerification Required
Enterprise storage team following ISO/IEC 27040 sanitization policy

At A Glance

Published By
ISO/IEC JTC 1/SC 27
Reference
ISO/IEC 27040, 2024 edition
Region
International
Passes
1
Verification
Required By The Standard, Locked On
Relative Run Time
2× a single pass

What The Software Writes

  1. Pass 1 Random data
  2. Verify Required by the standard. Every sector is read back and compared.
  3. Certify Signed certificate with device, method, result and operator

ISO/IEC 27040:2024 is the current second edition of the international standard Information technology — Security techniques — Storage security.

Published in January 2024 by ISO/IEC JTC 1/SC 27, ISO/IEC 27040:2024 provides technical requirements and guidance for planning, designing, documenting and implementing storage security across the lifecycle of storage technologies and environments. The standard addresses protection of data while stored and while transmitted across storage-related communication links, as well as security of storage devices, media, management activities, applications, services and end-of-life processes.

For organizations implementing secure data erasure and media sanitization, ISO/IEC 27040:2024 provides an important storage-security framework within which appropriate sanitization, disposal, reuse and control measures can be established.

Data Sanitization Pro (DSP) provides a dedicated ISO/IEC 27040:2024 Sanitization Method through the DSP Sanitization Engine, enabling controlled sanitization execution, verification, documentation and generation of an audit-ready sanitization certificate.

Important: ISO/IEC 27040:2024 is a storage-security standard, not a single fixed multi-pass disk-wiping algorithm. DSP's certificate documents the sanitization operation actually performed by DSP; it is not certification issued by ISO or IEC.

01

What Is ISO/IEC 27040:2024?

ISO/IEC 27040:2024 establishes a structured approach to storage security and risk mitigation.

The standard covers security considerations associated with:

  • Storage Devices
  • Storage Media
  • Storage Systems
  • Storage Networks
  • Storage Management
  • Applications And Services
  • Data Stored Within ICT Environments
  • Data Transferred Across Storage-Related Communication Links
  • User Activities
  • End-Of-Use And End-Of-Life Storage

ISO describes the standard as applicable to organizations and individuals involved in owning, operating, acquiring, managing or using storage devices, media, networks and related services.

This makes ISO/IEC 27040 different from a traditional data wiping algorithm.

It is fundamentally a storage-security framework, within which data sanitization and secure disposal form important operational considerations.

02

ISO/IEC 27040:2024 — Current Edition

EditionStatus
ISO/IEC 27040:2015Withdrawn
ISO/IEC 27040:2024Current published edition
Edition2nd Edition
PublicationJanuary 2024
StandardStorage Security
Technical CommitteeISO/IEC JTC 1/SC 27

ISO's official catalogue identifies ISO/IEC 27040:2024 as the published second edition and shows ISO/IEC 27040:2015 as withdrawn.

03

ISO/IEC 27040:2024 And Data Sanitization

Data sanitization is not simply a question of running a predefined number of overwrite passes.

A storage-security program needs to consider:

What data is stored? ↓ Where is it stored? ↓ What storage technology is being used? ↓ What security risk exists? ↓ What is the intended disposition? ↓ What sanitization or disposal technique is appropriate? ↓ How is the result verified? ↓ How is the operation documented?

This lifecycle approach aligns with the broader storage-security philosophy of ISO/IEC 27040:2024.

04

ISO/IEC 27040:2024 In Data Sanitization Pro

DSP provides a dedicated ISO/IEC 27040:2024 Sanitization Method within the DSP Sanitization Engine.

Rather than treating ISO/IEC 27040:2024 as a fixed three-pass, seven-pass or 35-pass wiping algorithm, DSP uses the standard as a storage-security-oriented sanitization methodology.

05

DSP Workflow

IDENTIFY Identify the storage device and relevant characteristics.

CLASSIFY Determine storage technology, media type and device context.

ASSESS Assess device accessibility, health and sanitization requirements.

SELECT Select the ISO/IEC 27040:2024 sanitization profile.

CHOOSE APPLICABLE TECHNIQUE Apply the appropriate sanitization approach for the storage technology and organizational requirements.

EXECUTE Run the selected sanitization operation through the DSP Sanitization Engine.

VERIFY Verify the execution result and identify errors or anomalies.

VALIDATE Determine whether the result meets the defined sanitization acceptance criteria.

DOCUMENT Record device, method, execution and verification information.

CERTIFY Generate an audit-ready DSP sanitization certificate.

06

ISO/IEC 27040 Is Not A Fixed Wiping Algorithm

This distinction is essential.

ISO/IEC 27040:2024 does not mean:

  • Always Overwrite Once
  • Always Overwrite Three Times
  • Always Overwrite Seven Times
  • Always Use Random Data
  • Always Use Zeros
  • Always Use A Particular Legacy Wiping Pattern

Instead, storage security needs to account for the characteristics and risks of the storage environment.

The appropriate sanitization technique can depend on:

  • Storage Technology
  • Media Characteristics
  • Data Sensitivity
  • Device Condition
  • Security Requirements
  • Intended Reuse
  • Disposal Requirements
  • Organizational Policy
  • Technical Capabilities
  • Required Assurance

This is particularly important for modern SSD and NVMe devices, where traditional logical overwriting may not address every physical flash location because of controller-managed storage architectures.

07

HDD Data Sanitization

For traditional magnetic HDDs, DSP can provide software-based sanitization operations while monitoring the storage device.

The workflow can include:

  • Drive Identification
  • Model Detection
  • Serial-Number Capture
  • Capacity Detection
  • Interface Identification
  • SMART Information
  • Temperature
  • Power-On Hours
  • Health Status
  • Bad-Sector Information
  • Sanitization Progress
  • Write Rate
  • Errors
  • Verification

The actual sanitization technique should be selected according to the organization's security requirements and the characteristics of the media.

08

SSD And NVMe Storage Sanitization

Modern solid-state storage requires a different technical approach from traditional magnetic HDDs.

SSD and NVMe devices may incorporate:

  • Flash Translation Layers
  • Wear Leveling
  • Garbage Collection
  • Spare Blocks
  • Over-Provisioned Capacity
  • Remapped Physical Locations
  • Controller-Level Management

Consequently, a conventional logical overwrite should not automatically be considered equivalent to complete physical sanitization of every historical flash location.

DSP can identify supported storage technologies and provide appropriate sanitization workflows.

For stronger sanitization requirements organizations may use device-specific sanitization capabilities or other applicable techniques rather than relying solely on repeated host-level writes.

This storage-technology distinction is particularly important in the context of modern media sanitization guidance such as NIST SP 800-88 Rev. 2 and IEEE 2883. NIST's current Rev. 2 specifically emphasizes program-level sanitization controls and recommends alignment with IEEE 2883, NSA specifications or organizationally approved standards for technology-specific techniques.

09

Storage Security Across The Device Lifecycle

ISO/IEC 27040:2024 takes a lifecycle-oriented approach to storage security.

DSP can support the operational portion of that lifecycle by providing structured device sanitization and evidence generation.

10

Storage Lifecycle

Procure

Storage technology and security requirements are identified.

Deploy

Storage devices and systems are placed into operation.

Operate

Security controls protect stored information and storage infrastructure.

Monitor

Device and storage conditions can be monitored.

Retire

Storage equipment reaches end of use.

Sanitize

Data is securely removed using the selected sanitization approach.

Verify

The sanitization result is assessed.

Reuse / Transfer / Dispose

The storage device is reused, transferred, retained or destroyed according to organizational requirements.

ISO/IEC 27040:2024 explicitly includes security considerations extending through the lifetime of devices and media and after end of use or end of life.

11

ISO/IEC 27040:2024 For IT Asset Disposition

Secure storage retirement is an important part of IT Asset Disposition.

Before a computer, server, HDD, SSD or other storage device is:

  • Reused
  • Refurbished
  • Resold
  • Transferred
  • Returned
  • Recycled
  • Disposed

the organization must determine how information stored on the device will be protected.

DSP can provide an operational sanitization workflow for ITAD environments.

12

ITAD Workflow

  1. 01Asset Intake
  2. 02Device Identification
  3. 03Storage Assessment
  4. 04Sanitization Method Selection
  5. 05Data Sanitization
  6. 06Verification
  7. 07Certificate Generation
  8. 08Asset Release / Reuse / Disposal

This provides documented evidence connecting the storage device to the sanitization operation.

13

ISO/IEC 27040:2024 And Storage Media

DSP supports sanitization workflows across a broad range of storage technologies, including:

Magnetic Storage

  • SATA HDD
  • SAS HDD
  • PATA/IDE HDD

Solid-State Storage

  • SATA SSD
  • NVMe SSD
  • M.2
  • U.2
  • mSATA
  • NGFF

Removable Storage

  • USB drives
  • Pen drives
  • SD cards
  • microSD
  • CompactFlash
  • CFexpress

Enterprise Storage

  • RAID
  • DAS
  • NAS
  • SAN
  • Server storage
  • Enterprise storage systems

The applicable sanitization technique should always be selected according to the actual storage architecture and security requirements.

Storage Security And Verification

A sanitization operation should produce more than a simple “Completed” message.

DSP can record operational and verification information such as:

Device Evidence

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Media type

Sanitization Evidence

  • Selected methodology
  • Sanitization technique
  • Execution status
  • Start time
  • Completion time
  • Processing information

Verification Evidence

  • Verification status
  • Read/write errors
  • Device response
  • Failed operations
  • Validation result

Audit Information

  • Operator
  • Workstation/system
  • Date and time
  • Case or asset information where configured
  • Report information
14

Device Health And Bad-Sector Intelligence

Storage security decisions should account for device condition.

DSP can assess and report:

  • SMART Health
  • Temperature
  • Power-On Hours
  • Read Errors
  • Write Errors
  • Bad Sectors
  • Unstable Sectors
  • Device Warnings
  • Inaccessible Regions

This is particularly important for retired HDDs and SSDs.

A device with inaccessible storage areas may require a different sanitization or disposal decision than a healthy device that can be fully addressed by the selected sanitization technique.

15

Verification vs Validation

DSP separates the concepts of verification and validation within the sanitization workflow.

16

Verification

Verification determines whether the selected sanitization operation completed as expected.

Examples include:

  • Completion Status
  • Error Detection
  • Device Response
  • Verification Checks
  • Operation Logs
17

Validation

Validation determines whether the resulting condition satisfies the organization's sanitization requirements.

For example:

  1. 01Operation Completed
  2. 02Verification Passed
  3. 03Result Reviewed
  4. 04Device Accepted

or:

  1. 01Operation Failed
  2. 02Result Rejected
  3. 03Different Technique / Escalation Required

This approach is particularly useful in enterprise and ITAD environments where sanitization decisions need documented evidence.

18

ISO/IEC 27040:2024 And NIST SP 800-88 Rev. 2

The relationship between the two standards is important.

ISO/IEC 27040:2024NIST SP 800-88 Rev. 2
International Storage-Security StandardU.S. NIST media-sanitization guideline
Broad Storage-Security LifecycleFocused media-sanitization program
Storage Devices, Media, Systems And Related SecurityMedia sanitization and disposal/reuse
Risk Mitigation And Storage ControlsClear, Purge and Destroy framework
Broader Storage-Security ContextMore specific sanitization guidance
International ISO/IEC FrameworkNIST publication

NIST explicitly states that Rev. 2 improves alignment between media-sanitization guidance and cybersecurity standards including ISO/IEC 27040.

Therefore, ISO/IEC 27040:2024 and NIST SP 800-88 Rev. 2 should not be presented as competing disk-wiping algorithms.

They address related security requirements from different perspectives.

19

ISO/IEC 27040:2024 And IEEE 2883

IEEE 2883 provides technology-specific storage-sanitization methods, while ISO/IEC 27040:2024 provides a broader storage-security framework.

This distinction becomes important for organizations that need to determine:

  1. 01Why Sanitization Is Required
  2. 02What Risk Must Be Addressed
  3. 03What Storage Technology Is Involved
  4. 04Which Technical Sanitization Method Should Be Applied
  5. 05How The Result Should Be Verified And Documented

NIST SP 800-88 Rev. 2 specifically points organizations toward IEEE 2883, NSA specifications or an organizationally approved standard for technology-specific sanitization techniques, except for its expanded treatment of Cryptographic Erase.

20

ISO/IEC 27040:2024 For Enterprise Storage Security

DSP can be used within enterprise storage-security workflows involving:

  • Enterprise IT
  • Data Centers
  • ITAD Providers
  • Refurbishers
  • Hardware Recyclers
  • Managed Service Providers
  • Government Organizations
  • Financial Institutions
  • Healthcare Organizations
  • Educational Institutions
  • Large Corporate Environments

Organizations can establish their own sanitization policies and use DSP to execute and document the applicable device-level sanitization operation.

21

Offline Storage Sanitization

DSP can support offline sanitization workflows for environments where storage devices cannot be connected to external cloud services.

This can be useful for:

  • Air-Gapped Environments
  • Government Facilities
  • Secure Laboratories
  • Enterprise Data Centers
  • Restricted Networks
  • Defense Environments
  • Sensitive ITAD Operations

The sanitization operation can be performed locally while maintaining the required operational and verification information for reporting.

22

Audit-Ready ISO/IEC 27040 Sanitization Certificate

DSP can generate an audit-ready sanitization certificate after the selected operation.

A report can contain:

Device Details

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Media type

Sanitization Details

  • ISO/IEC 27040:2024 methodology
  • Selected sanitization technique
  • Execution status
  • Start date/time
  • Completion date/time

Verification

  • Verification result
  • Errors
  • Device response
  • Validation outcome

Operator & Audit

  • Operator
  • System information
  • Asset/case information where configured
  • Audit metadata
  • Report generation details

Certification Statement

The certificate documents the sanitization operation performed by DSP.

It should not be represented as an ISO-issued certificate or as evidence that ISO/IEC has independently certified DSP.

23

ISO/IEC 27040:2024 Is Broader Than Data Erasure

A key advantage of positioning ISO/IEC 27040:2024 correctly is that it allows organizations to understand storage security as more than simply wiping a hard drive.

The broader storage-security environment can include:

Storage Architecture Storage Devices Storage Media Storage Networks Management Controls Applications & Services User Activities Data Protection End-of-Use Controls End-of-Life Sanitization

ISO describes the standard as addressing both stored information and information transferred across storage-related communication links, along with devices, media, management activities, applications and services.

DSP addresses the sanitization and evidence-generation component of this wider storage-security lifecycle.

24

ISO/IEC 27040:2024 In Data Sanitization Pro

Storage-Aware Approach

DSP can identify storage characteristics before selecting the applicable sanitization workflow.

Method-Specific Execution

The selected method is executed through the DSP Sanitization Engine.

Verification

Sanitization execution and verification results are recorded.

Device Intelligence

SMART and device-health information can provide additional context.

Bad-Sector Reporting

Storage access problems can be identified and documented.

Multi-Device Processing

Supported storage devices can be processed according to operational requirements.

Offline Operation

Suitable for controlled environments where internet connectivity is not required.

Audit-Ready Reporting

Generate documentation linking the device to its sanitization operation and verification result.

25

ISO/IEC 27040:2024 vs Traditional Data Wiping Methods

ApproachPrimary Focus
ISO/IEC 27040:2024Storage security and lifecycle risk management
NIST SP 800-88 Rev. 2Media sanitization program and sanitization decisions
IEEE 2883-2022Technology-specific storage sanitization
HMG IS5 EnhancedHistorical multi-pass overwrite methodology
DoD 5220.22-MHistorical U.S. government data-clearing methodology
GutmannHistorical multi-pass overwrite methodology
SchneierHistorical multi-pass overwrite methodology

This distinction helps prevent an important SEO and technical error:

ISO/IEC 27040:2024 should not be marketed as an “ISO 35-pass,” “ISO 7-pass” or “ISO 3-pass” wiping algorithm.

It is a storage-security standard.

26

25 Sanitization Methods In One Platform

ISO/IEC 27040:2024 can be part of a broader DSP sanitization environment containing multiple modern and historical sanitization methodologies.

Examples include:

Each method is maintained as a separate selectable DSP sanitization profile, with the execution and reporting appropriate to the selected methodology.

FAQ

ISO/IEC 27040 Questions

Is ISO/IEC 27040:2024 A Data Wiping Standard?

It is broader than a data wiping standard. ISO/IEC 27040:2024 is an international **storage-security standard** covering storage security across devices, media, systems, management and lifecycle activities.

Is ISO/IEC 27040:2024 Current?

Yes. ISO lists the 2024 second edition as published, while ISO/IEC 27040:2015 is withdrawn.

Does ISO/IEC 27040:2024 Define A Fixed Number Of Wiping Passes?

No. It should not be represented as a fixed-pass wiping algorithm.

Does ISO/IEC 27040:2024 Apply To SSD And NVMe?

Its storage-security scope is broader than any single media type. For actual sanitization, the selected technical method should account for the architecture and characteristics of the storage technology.

Is ISO/IEC 27040 The Same As NIST SP 800-88?

No. They are different documents with different scopes, although NIST SP 800-88 Rev. 2 explicitly aligns its program guidance with standards including ISO/IEC 27040.

Is ISO/IEC 27040 The Same As IEEE 2883?

No. IEEE 2883 focuses on storage sanitization methods and technology-specific requirements, while ISO/IEC 27040 provides a broader storage-security framework.

Does DSP Provide An ISO/IEC 27040 Certificate?

DSP can generate an **audit-ready sanitization certificate documenting the operation performed by DSP**. It is not an ISO-issued certificate.

Can ISO/IEC 27040:2024 Be Used For ITAD?

Yes, its storage-security lifecycle scope includes considerations extending through end of use and end of life, making it relevant to storage retirement and secure sanitization programs.

ISO/IEC 27040:2024 — Storage Security With Verifiable Sanitization

Data Sanitization Pro runs all 25 standards offline and verifies the result.