Magnetic Storage
- SATA HDD
- SAS HDD
- PATA/IDE HDD
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
International Storage Security Standard For Data Protection, Sanitization & End-Of-Life Media Management

ISO/IEC 27040:2024 is the current second edition of the international standard Information technology — Security techniques — Storage security.
Published in January 2024 by ISO/IEC JTC 1/SC 27, ISO/IEC 27040:2024 provides technical requirements and guidance for planning, designing, documenting and implementing storage security across the lifecycle of storage technologies and environments. The standard addresses protection of data while stored and while transmitted across storage-related communication links, as well as security of storage devices, media, management activities, applications, services and end-of-life processes.
For organizations implementing secure data erasure and media sanitization, ISO/IEC 27040:2024 provides an important storage-security framework within which appropriate sanitization, disposal, reuse and control measures can be established.
Data Sanitization Pro (DSP) provides a dedicated ISO/IEC 27040:2024 Sanitization Method through the DSP Sanitization Engine, enabling controlled sanitization execution, verification, documentation and generation of an audit-ready sanitization certificate.
Important: ISO/IEC 27040:2024 is a storage-security standard, not a single fixed multi-pass disk-wiping algorithm. DSP's certificate documents the sanitization operation actually performed by DSP; it is not certification issued by ISO or IEC.
ISO/IEC 27040:2024 establishes a structured approach to storage security and risk mitigation.
The standard covers security considerations associated with:
ISO describes the standard as applicable to organizations and individuals involved in owning, operating, acquiring, managing or using storage devices, media, networks and related services.
This makes ISO/IEC 27040 different from a traditional data wiping algorithm.
It is fundamentally a storage-security framework, within which data sanitization and secure disposal form important operational considerations.
| Edition | Status |
|---|---|
| ISO/IEC 27040:2015 | Withdrawn |
| ISO/IEC 27040:2024 | Current published edition |
| Edition | 2nd Edition |
| Publication | January 2024 |
| Standard | Storage Security |
| Technical Committee | ISO/IEC JTC 1/SC 27 |
ISO's official catalogue identifies ISO/IEC 27040:2024 as the published second edition and shows ISO/IEC 27040:2015 as withdrawn.
Data sanitization is not simply a question of running a predefined number of overwrite passes.
A storage-security program needs to consider:
What data is stored? ↓ Where is it stored? ↓ What storage technology is being used? ↓ What security risk exists? ↓ What is the intended disposition? ↓ What sanitization or disposal technique is appropriate? ↓ How is the result verified? ↓ How is the operation documented?
This lifecycle approach aligns with the broader storage-security philosophy of ISO/IEC 27040:2024.
DSP provides a dedicated ISO/IEC 27040:2024 Sanitization Method within the DSP Sanitization Engine.
Rather than treating ISO/IEC 27040:2024 as a fixed three-pass, seven-pass or 35-pass wiping algorithm, DSP uses the standard as a storage-security-oriented sanitization methodology.
IDENTIFY Identify the storage device and relevant characteristics.
CLASSIFY Determine storage technology, media type and device context.
ASSESS Assess device accessibility, health and sanitization requirements.
SELECT Select the ISO/IEC 27040:2024 sanitization profile.
CHOOSE APPLICABLE TECHNIQUE Apply the appropriate sanitization approach for the storage technology and organizational requirements.
EXECUTE Run the selected sanitization operation through the DSP Sanitization Engine.
VERIFY Verify the execution result and identify errors or anomalies.
VALIDATE Determine whether the result meets the defined sanitization acceptance criteria.
DOCUMENT Record device, method, execution and verification information.
CERTIFY Generate an audit-ready DSP sanitization certificate.
This distinction is essential.
ISO/IEC 27040:2024 does not mean:
Instead, storage security needs to account for the characteristics and risks of the storage environment.
The appropriate sanitization technique can depend on:
This is particularly important for modern SSD and NVMe devices, where traditional logical overwriting may not address every physical flash location because of controller-managed storage architectures.
For traditional magnetic HDDs, DSP can provide software-based sanitization operations while monitoring the storage device.
The workflow can include:
The actual sanitization technique should be selected according to the organization's security requirements and the characteristics of the media.
Modern solid-state storage requires a different technical approach from traditional magnetic HDDs.
SSD and NVMe devices may incorporate:
Consequently, a conventional logical overwrite should not automatically be considered equivalent to complete physical sanitization of every historical flash location.
DSP can identify supported storage technologies and provide appropriate sanitization workflows.
For stronger sanitization requirements organizations may use device-specific sanitization capabilities or other applicable techniques rather than relying solely on repeated host-level writes.
This storage-technology distinction is particularly important in the context of modern media sanitization guidance such as NIST SP 800-88 Rev. 2 and IEEE 2883. NIST's current Rev. 2 specifically emphasizes program-level sanitization controls and recommends alignment with IEEE 2883, NSA specifications or organizationally approved standards for technology-specific techniques.
ISO/IEC 27040:2024 takes a lifecycle-oriented approach to storage security.
DSP can support the operational portion of that lifecycle by providing structured device sanitization and evidence generation.
Storage technology and security requirements are identified.
Storage devices and systems are placed into operation.
Security controls protect stored information and storage infrastructure.
Device and storage conditions can be monitored.
Storage equipment reaches end of use.
Data is securely removed using the selected sanitization approach.
The sanitization result is assessed.
The storage device is reused, transferred, retained or destroyed according to organizational requirements.
ISO/IEC 27040:2024 explicitly includes security considerations extending through the lifetime of devices and media and after end of use or end of life.
Secure storage retirement is an important part of IT Asset Disposition.
Before a computer, server, HDD, SSD or other storage device is:
the organization must determine how information stored on the device will be protected.
DSP can provide an operational sanitization workflow for ITAD environments.
This provides documented evidence connecting the storage device to the sanitization operation.
DSP supports sanitization workflows across a broad range of storage technologies, including:
The applicable sanitization technique should always be selected according to the actual storage architecture and security requirements.
A sanitization operation should produce more than a simple “Completed” message.
DSP can record operational and verification information such as:
Storage security decisions should account for device condition.
DSP can assess and report:
This is particularly important for retired HDDs and SSDs.
A device with inaccessible storage areas may require a different sanitization or disposal decision than a healthy device that can be fully addressed by the selected sanitization technique.
DSP separates the concepts of verification and validation within the sanitization workflow.
Verification determines whether the selected sanitization operation completed as expected.
Examples include:
Validation determines whether the resulting condition satisfies the organization's sanitization requirements.
For example:
or:
This approach is particularly useful in enterprise and ITAD environments where sanitization decisions need documented evidence.
The relationship between the two standards is important.
| ISO/IEC 27040:2024 | NIST SP 800-88 Rev. 2 |
|---|---|
| International Storage-Security Standard | U.S. NIST media-sanitization guideline |
| Broad Storage-Security Lifecycle | Focused media-sanitization program |
| Storage Devices, Media, Systems And Related Security | Media sanitization and disposal/reuse |
| Risk Mitigation And Storage Controls | Clear, Purge and Destroy framework |
| Broader Storage-Security Context | More specific sanitization guidance |
| International ISO/IEC Framework | NIST publication |
NIST explicitly states that Rev. 2 improves alignment between media-sanitization guidance and cybersecurity standards including ISO/IEC 27040.
Therefore, ISO/IEC 27040:2024 and NIST SP 800-88 Rev. 2 should not be presented as competing disk-wiping algorithms.
They address related security requirements from different perspectives.
IEEE 2883 provides technology-specific storage-sanitization methods, while ISO/IEC 27040:2024 provides a broader storage-security framework.
This distinction becomes important for organizations that need to determine:
NIST SP 800-88 Rev. 2 specifically points organizations toward IEEE 2883, NSA specifications or an organizationally approved standard for technology-specific sanitization techniques, except for its expanded treatment of Cryptographic Erase.
DSP can be used within enterprise storage-security workflows involving:
Organizations can establish their own sanitization policies and use DSP to execute and document the applicable device-level sanitization operation.
DSP can support offline sanitization workflows for environments where storage devices cannot be connected to external cloud services.
This can be useful for:
The sanitization operation can be performed locally while maintaining the required operational and verification information for reporting.
DSP can generate an audit-ready sanitization certificate after the selected operation.
A report can contain:
The certificate documents the sanitization operation performed by DSP.
It should not be represented as an ISO-issued certificate or as evidence that ISO/IEC has independently certified DSP.
A key advantage of positioning ISO/IEC 27040:2024 correctly is that it allows organizations to understand storage security as more than simply wiping a hard drive.
The broader storage-security environment can include:
Storage Architecture Storage Devices Storage Media Storage Networks Management Controls Applications & Services User Activities Data Protection End-of-Use Controls End-of-Life Sanitization
ISO describes the standard as addressing both stored information and information transferred across storage-related communication links, along with devices, media, management activities, applications and services.
DSP addresses the sanitization and evidence-generation component of this wider storage-security lifecycle.
DSP can identify storage characteristics before selecting the applicable sanitization workflow.
The selected method is executed through the DSP Sanitization Engine.
Sanitization execution and verification results are recorded.
SMART and device-health information can provide additional context.
Storage access problems can be identified and documented.
Supported storage devices can be processed according to operational requirements.
Suitable for controlled environments where internet connectivity is not required.
Generate documentation linking the device to its sanitization operation and verification result.
| Approach | Primary Focus |
|---|---|
| ISO/IEC 27040:2024 | Storage security and lifecycle risk management |
| NIST SP 800-88 Rev. 2 | Media sanitization program and sanitization decisions |
| IEEE 2883-2022 | Technology-specific storage sanitization |
| HMG IS5 Enhanced | Historical multi-pass overwrite methodology |
| DoD 5220.22-M | Historical U.S. government data-clearing methodology |
| Gutmann | Historical multi-pass overwrite methodology |
| Schneier | Historical multi-pass overwrite methodology |
This distinction helps prevent an important SEO and technical error:
ISO/IEC 27040:2024 should not be marketed as an “ISO 35-pass,” “ISO 7-pass” or “ISO 3-pass” wiping algorithm.
It is a storage-security standard.
ISO/IEC 27040:2024 can be part of a broader DSP sanitization environment containing multiple modern and historical sanitization methodologies.
Examples include:
Each method is maintained as a separate selectable DSP sanitization profile, with the execution and reporting appropriate to the selected methodology.
It is broader than a data wiping standard. ISO/IEC 27040:2024 is an international **storage-security standard** covering storage security across devices, media, systems, management and lifecycle activities.
Yes. ISO lists the 2024 second edition as published, while ISO/IEC 27040:2015 is withdrawn.
No. It should not be represented as a fixed-pass wiping algorithm.
Its storage-security scope is broader than any single media type. For actual sanitization, the selected technical method should account for the architecture and characteristics of the storage technology.
No. They are different documents with different scopes, although NIST SP 800-88 Rev. 2 explicitly aligns its program guidance with standards including ISO/IEC 27040.
No. IEEE 2883 focuses on storage sanitization methods and technology-specific requirements, while ISO/IEC 27040 provides a broader storage-security framework.
DSP can generate an **audit-ready sanitization certificate documenting the operation performed by DSP**. It is not an ISO-issued certificate.
Yes, its storage-security lifecycle scope includes considerations extending through end of use and end of life, making it relevant to storage retirement and secure sanitization programs.
Data Sanitization Pro runs all 25 standards offline and verifies the result.