Device Information
- Manufacturer
- Model
- Serial number
- Capacity
- Interface
- Firmware
- Media type
CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883
New Zealand Government Information Security & Media Sanitization

NZISM — New Zealand Information Security Manual is the New Zealand Government's manual for information assurance and information-systems security. It is maintained by the New Zealand National Cyber Security Centre (NCSC) and provides baseline and additional security controls for New Zealand Government agencies. Crown entities, local government and private-sector organizations are also encouraged to use it.
For secure data erasure and media handling, NZISM provides specific guidance and controls covering:
Data Sanitization Pro (DSP) provides a dedicated NZISM Sanitization Method through the DSP Sanitization Engine, allowing organizations to execute an applicable sanitization workflow, verify the result, document the operation and generate an audit-ready sanitization certificate.
Important: NZISM is a government information-security manual and control framework, not a single universal multi-pass wiping algorithm. DSP's certificate documents the sanitization operation performed by DSP; it is not an NCSC or New Zealand Government certification.
The New Zealand Information Security Manual (NZISM) establishes information-security controls and guidance for protecting New Zealand Government information and systems.
The NZISM is based on security threat and risk assessment and provides:
The current NZISM includes dedicated provisions for media and IT equipmentsanitization, making it directly relevant to secure data erasure, storage-media reuse and controlled disposal.
The New Zealand NCSC continues to maintain and update NZISM.
The NCSC announced NZISM v3.9 in May 2025, with updates to several chapters and sections.
For media sanitization, the current NZISM material identifies Section 13.4 — Media and IT EquipmentSanitization and related disposal controls in Section 13.6.
NZISM treats sanitization as a security process rather than simply deleting files or formatting a device.
The current NZISM states that sanitization procedures are intended to prevent unauthorized access to classified information and that approved sanitization methods should provide a high level of assurance that remnant data is not left on the media.
The manual also specifically requires that an overwrite process be read back to verify successful completion. If sanitization cannot be successfully completed, destruction is required.
If the sanitization process cannot be successfully completed:
This is one of the most important technical distinctions for the DSP website.
NZISM does not mean:
Instead, NZISM provides media-specific security controls and sanitization requirements.
The appropriate treatment depends on:
The current NZISM explicitly distinguishes between different categories of media and requires destruction for media that cannot be effectively sanitized.
DSP provides a dedicated NZISM Sanitization Method through the DSP Sanitization Engine.
Identify the storage device.
Determine media type, storage technology and relevant device characteristics.
Assess whether the device can be successfully sanitized using an applicable method.
Select the NZISM sanitization profile.
Run the applicable sanitization operation through the DSP Sanitization Engine.
Read back and verify the sanitization result.
Determine whether the device satisfies the defined sanitization requirements.
Record the operation, device and verification information.
Generate an audit-ready DSP sanitization certificate.
Flag the device for the applicable destruction/disposal workflow.
The current NZISM contains specific controls for non-volatile magnetic media.
For applicable magnetic media, the historical/current NZISM framework has differentiated requirements according to the age/capacity of the media.
The current manual's sanitization requirements should therefore be implemented according to the applicable NZISM version, media classification and organizational policy, rather than converting NZISM into a generic “three-pass” marketing claim.
This is particularly important because older NZISM versions contained explicit magnetic-media overwrite rules that differed according to media characteristics. The current NZISM should be treated as the controlling reference for current implementations.
One of the strongest technical characteristics of the NZISM sanitization approach is its explicit emphasis on read-back verification.
The current NZISM states that when sanitizing media, it is necessary to read back the contents to verify that the overwrite process completed successfully.
DSP can therefore record:
This provides stronger evidence than a simple application status such as “Wipe Complete.”
NZISM takes a clear position when sanitization cannot be successfully completed.
The current NZISM states that if the sanitization process cannot be successfully completed, destruction will be necessary.
This is particularly relevant for damaged or inaccessible storage.
DSP can identify conditions such as:
The result can then be documented for an appropriate destroy / dispose decision.
This is a major technical distinction.
Current NZISM specifically identifies certain storage types that cannot be effectively sanitized under its applicable controls and therefore must be destroyed prior to disposal.
The current Section 13.4 lists:
among media requiring destruction where effective sanitization is not possible.
Therefore, the DSP website should not claim that a generic software overwrite makes every SSD/NVMe device NZISM-sanitized.
Solid-state storage can use:
A host-level overwrite may therefore address logical storage without necessarily overwriting every historical physical flash location.
The NZISM specifically recognizes the difficulty of effectively sanitizing flash and solid-state storage.
This makes the NZISM approach particularly relevant to modern data-erasure workflows because it does not assume that the same overwrite technique is suitable for every storage technology.
Hybrid storage devices can combine magnetic and solid-state components.
The applicable NZISM controls must therefore be considered according to the actual storage architecture.
DSP can identify the storage type and allow the operator to determine the appropriate sanitization or destruction workflow.
The key principle is:
Storage architecture determines the sanitization decision.
NZISM addresses not only individual storage media but also IT equipment containing storage media.
This is important for:
The NZISM framework requires agencies to address sanitization or destruction before equipment is declassified and released for disposal.
DSP can support the device-level sanitization component of this process.
Sanitization and declassification are related but should not be treated as identical.
NZISM requires agencies to declassify media and IT equipment before disposal into the public domain. Media that cannot be effectively sanitized or declassified must be destroyed rather than released.
This provides a broader lifecycle context around data erasure.
NZISM is particularly relevant to secure IT asset retirement because the NCSC's current asset-lifecycle guidance states that organizations should ensure data is removed before devices are sold, disposed of or reused. It also recommends sanitizing devices before internal reuse.
DSP can support an ITAD workflow such as:
This provides a documented connection between the physical asset and its sanitization result.
For supported magnetic HDDs, DSP can capture device information before and during sanitization.
This provides both sanitization evidence and device-level context.
Bad sectors can directly affect whether a storage device can be successfully sanitized.
DSP can detect and document:
Where the selected sanitization operation cannot successfully address required storage locations, the device can be flagged for the applicable destruction workflow rather than incorrectly marked as successfully sanitized.
This is consistent with the NZISM principle that unsuccessful sanitization requires destruction.
A factory reset should not be presented as equivalent to secure media sanitization.
The current NZISM explicitly states that “factory reset” or similar terminology does not constitutesanitizationof media.
Therefore:
Factory Reset≠NZISM Media Sanitization
A proper sanitization workflow requires an appropriate sanitization operation and verification.
DSP can document the sanitization operation and its read-back verification.
However, NZISM's historical/current guidance has also recognized the value of independent verification: earlier NZISM versions stated that agencies should verify sanitized media using a different product from the one that performed the initial sanitization.
For organizations requiring this additional assurance, an independent verification process can therefore be incorporated into the organization's sanitization policy.
This should be represented as an organizational assurance process, not as a claim that every DSP operation automatically constitutes independent NZISM verification.
Where sanitization is not technically feasible, NZISM provides a destruction path.
The current manual identifies media types that must be destroyed where they cannot be effectively sanitized and includes requirements around destruction equipment and approved destruction facilities.
DSP therefore works best as part of a complete workflow:
This is especially important for:
| Feature | NZISM | NIST SP 800-88 Rev. 2 |
|---|---|---|
| Origin | New Zealand Government | U.S. NIST |
| Scope | Government information security | Media sanitization |
| Overall Approach | Security controls and risk management | Sanitization program and methods |
| Media Sanitization | Dedicated NZISM controls | Clear / Purge / Destroy |
| Verification | Read-back verification is specifically addressed | Verification and validation framework |
| Failed Sanitization | Destruction required | Escalation / different technique / destruction as appropriate |
| SSD/flash | Specific restrictions and destruction requirements | Technology-specific sanitization considerations |
| Disposal | Declassification + disposal controls | Sanitization/disposition framework |
They are therefore not competing wiping algorithms.
NZISM is a broader New Zealand Government security framework containing specific media-management and sanitization controls.
IEEE 2883-2022 focuses on storage sanitization methods and technology-specific requirements.
NZISM provides the broader New Zealand Government information-security context and specifies controls for sanitization, destruction and disposal.
A practical workflow can therefore be:
DSP can provide the operational sanitization component within this type of workflow.
NZISM is particularly relevant to:
The NCSC states that NZISM is specifically intended for New Zealand Government agencies while also encouraging Crown entities, local government and private-sector organizations to use it.
DSP can support offline sanitization workflows where internet connectivity is restricted or unavailable.
This can be useful for:
The sanitization operation can be executed locally while maintaining device and verification information for reporting.
DSP can generate an audit-ready sanitization certificate documenting the operation performed by DSP.
The DSP certificate is evidence of the sanitization operation performed by DSP.
It is not an NCSC-issued NZISM certificate and DSP should not be marketed as “NZISM certified” unless a separate, independently established certification exists.
NZISM's sanitization requirements are particularly relevant when media is:
The NCSC's current asset-lifecycle guidance also recommends sanitizing devices before reuse or repurposing.
DSP can provide the operational evidence required to show what sanitization method was executed and what verification result was obtained.
DSP provides a dedicated NZISM sanitization profile rather than treating NZISM as a generic overwrite preset.
The sanitization workflow can account for differences between magnetic, flash and other supported storage technologies.
DSP can verify the completed sanitization operation.
Failed sanitization can be identified and documented.
Storage errors and inaccessible regions can be reported.
SMART and storage-health information can accompany the sanitization record.
Suitable for controlled environments without internet dependency.
Supported devices can be processed according to operational requirements.
Generate device-level documentation connecting the storage asset to its sanitization result.
The most accurate way to understand the NZISM approach is:
→ Apply the applicable sanitization method → Read back and verify → Validate → Document → Declassify/approve as required → Reuse or dispose
→ Destroy the media → Document destruction → Follow declassification and disposal procedures
This is substantially different from a simple “run three passes and issue a certificate” model.
NZISM is one of the government-oriented sanitization frameworks supported through DSP.
The DSP Sanitization Engine can provide separate selectable profiles for modern and historical methodologies such as:
Each methodology remains a separate selectable DSP sanitization profile, with its applicable execution, verification and reporting workflow.
NZISM is the **New Zealand Information Security Manual**, maintained by the New Zealand National Cyber Security Centre. It provides information-security controls and guidance for New Zealand Government agencies.
No. NZISM is a broader information-security manual containing specific controls for media sanitization, destruction and disposal.
No. Its sanitization requirements vary according to media type, technology and security requirements.
Yes. The current media-sanitization section specifically states that media should be read back to verify that an overwrite process completed successfully.
The current NZISM states that if sanitization cannot be successfully completed, destruction will be necessary.
The current NZISM specifically identifies flash memory and solid-state/hybrid storage among media that must be destroyed where they cannot be effectively sanitized. Therefore, a generic software overwrite should not be marketed as automatically making every SSD or flash device NZISM-sanitized.
No. NZISM explicitly states that factory reset or similar operations do not constitute media sanitization.
DSP can generate an **audit-ready sanitization certificate documenting the operation performed by DSP**.
No. It is a DSP-generated record of the sanitization operation and verification result.
Yes. NZISM contains controls covering media sanitization, destruction, declassification and disposal, making it directly relevant to secure IT asset retirement workflows.
Data Sanitization Pro runs all 25 standards offline and verifies the result.