CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standard 23 Of 25 · Government And Defence

NZISM — New Zealand Information Security Manual

New Zealand Government Information Security & Media Sanitization

New Zealand3 PassesVerification Available
New Zealand agency IT team following NZISM sanitisation

At A Glance

Published By
Government Communications Security Bureau (GCSB)
Reference
New Zealand Information Security Manual
Region
New Zealand
Passes
3
Verification
Available On Every Run
Relative Run Time
3× a single pass

What The Software Writes

  1. Pass 1 Fixed pattern 0x00
  2. Pass 2 Fixed pattern 0xFF
  3. Pass 3 Random data
  4. Verify Read back of the final pass, available on every run.
  5. Certify Signed certificate with device, method, result and operator

NZISM — New Zealand Information Security Manual is the New Zealand Government's manual for information assurance and information-systems security. It is maintained by the New Zealand National Cyber Security Centre (NCSC) and provides baseline and additional security controls for New Zealand Government agencies. Crown entities, local government and private-sector organizations are also encouraged to use it.

For secure data erasure and media handling, NZISM provides specific guidance and controls covering:

  • Media Sanitization
  • IT Equipment Sanitization
  • Media Destruction
  • Media Disposal
  • Verification Of Sanitization
  • Handling Of Media That Cannot Be Sanitized
  • Classification And Declassification
  • Reuse And Redeployment
  • Secure Disposal

Data Sanitization Pro (DSP) provides a dedicated NZISM Sanitization Method through the DSP Sanitization Engine, allowing organizations to execute an applicable sanitization workflow, verify the result, document the operation and generate an audit-ready sanitization certificate.

Important: NZISM is a government information-security manual and control framework, not a single universal multi-pass wiping algorithm. DSP's certificate documents the sanitization operation performed by DSP; it is not an NCSC or New Zealand Government certification.

01

What Is NZISM?

The New Zealand Information Security Manual (NZISM) establishes information-security controls and guidance for protecting New Zealand Government information and systems.

The NZISM is based on security threat and risk assessment and provides:

  • Essential Or Baseline Controls
  • Additional Good-Practice Controls
  • Recommended Practices
  • Security Implementation Guidance
  • Information-Security Assurance Requirements
  • Media-Management Requirements
  • Decommissioning And Disposal Controls

The current NZISM includes dedicated provisions for media and IT equipmentsanitization, making it directly relevant to secure data erasure, storage-media reuse and controlled disposal.

02

NZISM Current Version

The New Zealand NCSC continues to maintain and update NZISM.

The NCSC announced NZISM v3.9 in May 2025, with updates to several chapters and sections.

For media sanitization, the current NZISM material identifies Section 13.4 — Media and IT EquipmentSanitization and related disposal controls in Section 13.6.

03

NZISM Media Sanitization

NZISM treats sanitization as a security process rather than simply deleting files or formatting a device.

The current NZISM states that sanitization procedures are intended to prevent unauthorized access to classified information and that approved sanitization methods should provide a high level of assurance that remnant data is not left on the media.

The manual also specifically requires that an overwrite process be read back to verify successful completion. If sanitization cannot be successfully completed, destruction is required.

04

Core NZISM Sanitization Principle

  1. 01Sanitize
  2. 02Read Back
  3. 03Verify
  4. 04Accept

If the sanitization process cannot be successfully completed:

Sanitization FailureDestroy Media
05

NZISM Is Not A Fixed-Pass Wiping Algorithm

This is one of the most important technical distinctions for the DSP website.

NZISM does not mean:

  • Always Use One Pass
  • Always Use Three Passes
  • Always Use Seven Passes
  • Always Use Random Data
  • Always Use Zeros
  • Always Use A Particular Legacy Overwrite Pattern

Instead, NZISM provides media-specific security controls and sanitization requirements.

The appropriate treatment depends on:

  • Media Type
  • Storage Technology
  • Classification
  • Device Condition
  • Intended Reuse
  • Sanitization Capability
  • Verification Result
  • Disposal Requirements

The current NZISM explicitly distinguishes between different categories of media and requires destruction for media that cannot be effectively sanitized.

06

NZISM Sanitization Workflow In Data Sanitization Pro

DSP provides a dedicated NZISM Sanitization Method through the DSP Sanitization Engine.

07

DSP Workflow

Identify

Identify the storage device.

Classify

Determine media type, storage technology and relevant device characteristics.

Assess

Assess whether the device can be successfully sanitized using an applicable method.

Select

Select the NZISM sanitization profile.

Execute

Run the applicable sanitization operation through the DSP Sanitization Engine.

Verify

Read back and verify the sanitization result.

Validate

Determine whether the device satisfies the defined sanitization requirements.

Document

Record the operation, device and verification information.

Certify

Generate an audit-ready DSP sanitization certificate.

If Sanitization Fails

Flag the device for the applicable destruction/disposal workflow.

08

NZISM And Non-Volatile Magnetic Media

The current NZISM contains specific controls for non-volatile magnetic media.

For applicable magnetic media, the historical/current NZISM framework has differentiated requirements according to the age/capacity of the media.

The current manual's sanitization requirements should therefore be implemented according to the applicable NZISM version, media classification and organizational policy, rather than converting NZISM into a generic “three-pass” marketing claim.

This is particularly important because older NZISM versions contained explicit magnetic-media overwrite rules that differed according to media characteristics. The current NZISM should be treated as the controlling reference for current implementations.

09

Read-Back Verification

One of the strongest technical characteristics of the NZISM sanitization approach is its explicit emphasis on read-back verification.

The current NZISM states that when sanitizing media, it is necessary to read back the contents to verify that the overwrite process completed successfully.

DSP can therefore record:

  • Sanitization Completion
  • Verification Status
  • Read-Back Result
  • Read Errors
  • Write Errors
  • Failed Regions
  • Device Response
  • Validation Result
10

Sanitization Evidence

  1. 01Write / Sanitize
  2. 02Read Back
  3. 03Compare / Verify
  4. 04Pass Or Fail

This provides stronger evidence than a simple application status such as “Wipe Complete.”

11

Sanitization Failure And Destruction

NZISM takes a clear position when sanitization cannot be successfully completed.

The current NZISM states that if the sanitization process cannot be successfully completed, destruction will be necessary.

This is particularly relevant for damaged or inaccessible storage.

DSP can identify conditions such as:

  • Bad Sectors
  • Read Failures
  • Write Failures
  • Unstable Sectors
  • Inaccessible Regions
  • Device Communication Errors
  • Sanitization Failures

The result can then be documented for an appropriate destroy / dispose decision.

12

NZISM And SSD / Flash Storage

This is a major technical distinction.

Current NZISM specifically identifies certain storage types that cannot be effectively sanitized under its applicable controls and therefore must be destroyed prior to disposal.

The current Section 13.4 lists:

  • Flash Memory
  • Solid-State Storage Devices
  • Hybrid Storage Devices
  • Rom
  • Prom
  • Eprom
  • Eeprom
  • Optical Discs
  • Microfilm
  • Microfiche
  • Certain Faulty Magnetic Media

among media requiring destruction where effective sanitization is not possible.

Therefore, the DSP website should not claim that a generic software overwrite makes every SSD/NVMe device NZISM-sanitized.

13

Why SSD Sanitization Is Different

Solid-state storage can use:

  • Flash Translation Layers
  • Wear Leveling
  • Garbage Collection
  • Spare NAND Blocks
  • Over-Provisioning
  • Remapping
  • Controller-Managed Physical Locations

A host-level overwrite may therefore address logical storage without necessarily overwriting every historical physical flash location.

The NZISM specifically recognizes the difficulty of effectively sanitizing flash and solid-state storage.

This makes the NZISM approach particularly relevant to modern data-erasure workflows because it does not assume that the same overwrite technique is suitable for every storage technology.

14

NZISM And Hybrid Storage

Hybrid storage devices can combine magnetic and solid-state components.

The applicable NZISM controls must therefore be considered according to the actual storage architecture.

DSP can identify the storage type and allow the operator to determine the appropriate sanitization or destruction workflow.

The key principle is:

Storage architecture determines the sanitization decision.

15

NZISM And IT Equipment Sanitization

NZISM addresses not only individual storage media but also IT equipment containing storage media.

This is important for:

  • Desktop Computers
  • Laptops
  • Servers
  • Storage Appliances
  • Enterprise Systems
  • Network Equipment
  • Other IT Equipment Containing Information-Bearing Media

The NZISM framework requires agencies to address sanitization or destruction before equipment is declassified and released for disposal.

DSP can support the device-level sanitization component of this process.

16

NZISM Declassification And Disposal

Sanitization and declassification are related but should not be treated as identical.

NZISM requires agencies to declassify media and IT equipment before disposal into the public domain. Media that cannot be effectively sanitized or declassified must be destroyed rather than released.

17

NZISM Disposal Concept

  1. 01Identify Asset
  2. 02Determine Classification
  3. 03Sanitize Or Destroy
  4. 04Verify
  5. 05Declassification / Approval
  6. 06Release / Disposal

This provides a broader lifecycle context around data erasure.

18

NZISM For IT Asset Disposition

NZISM is particularly relevant to secure IT asset retirement because the NCSC's current asset-lifecycle guidance states that organizations should ensure data is removed before devices are sold, disposed of or reused. It also recommends sanitizing devices before internal reuse.

DSP can support an ITAD workflow such as:

  1. 01Asset Intake
  2. 02Device Identification
  3. 03Storage Assessment
  4. 04NZISM Sanitization
  5. 05Read-Back Verification
  6. 06Validation
  7. 07Certificate
  8. 08Reuse / Redeploy / Destroy

This provides a documented connection between the physical asset and its sanitization result.

19

NZISM For HDD Sanitization

For supported magnetic HDDs, DSP can capture device information before and during sanitization.

Device Information

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Firmware
  • Media type

Health Information

  • SMART status
  • Temperature
  • Power-on hours
  • Read errors
  • Write errors
  • Bad sectors
  • Device warnings

Sanitization Information

  • NZISM profile
  • Sanitization method
  • Progress
  • Write rate
  • Elapsed time
  • Verification status
  • Completion status

This provides both sanitization evidence and device-level context.

20

NZISM Bad-Sector Handling

Bad sectors can directly affect whether a storage device can be successfully sanitized.

DSP can detect and document:

  • Existing Bad Sectors
  • Read Failures
  • Write Failures
  • Unstable Sectors
  • Inaccessible Regions
  • Sanitization Exceptions

Where the selected sanitization operation cannot successfully address required storage locations, the device can be flagged for the applicable destruction workflow rather than incorrectly marked as successfully sanitized.

This is consistent with the NZISM principle that unsuccessful sanitization requires destruction.

21

NZISM And Factory Reset

A factory reset should not be presented as equivalent to secure media sanitization.

The current NZISM explicitly states that “factory reset” or similar terminology does not constitutesanitizationof media.

Therefore:

Factory Reset≠NZISM Media Sanitization

A proper sanitization workflow requires an appropriate sanitization operation and verification.

22

NZISM Verification And Independent Assurance

DSP can document the sanitization operation and its read-back verification.

However, NZISM's historical/current guidance has also recognized the value of independent verification: earlier NZISM versions stated that agencies should verify sanitized media using a different product from the one that performed the initial sanitization.

For organizations requiring this additional assurance, an independent verification process can therefore be incorporated into the organization's sanitization policy.

23

DSP + Independent Verification

  1. 01DSP Sanitization
  2. 02DSP Verification
  3. 03Independent Verification, Where Required
  4. 04Validation
  5. 05Final Record

This should be represented as an organizational assurance process, not as a claim that every DSP operation automatically constitutes independent NZISM verification.

24

NZISM And Media Destruction

Where sanitization is not technically feasible, NZISM provides a destruction path.

The current manual identifies media types that must be destroyed where they cannot be effectively sanitized and includes requirements around destruction equipment and approved destruction facilities.

DSP therefore works best as part of a complete workflow:

Sanitize When PossibleDestroy When Sanitization Is Not Effective

This is especially important for:

  • SSDs
  • Flash Media
  • Faulty Storage
  • Unrecoverable/inaccessible Media
  • Media Subject To Higher Security Requirements
25

NZISM vs NIST SP 800-88 Rev. 2

FeatureNZISMNIST SP 800-88 Rev. 2
OriginNew Zealand GovernmentU.S. NIST
ScopeGovernment information securityMedia sanitization
Overall ApproachSecurity controls and risk managementSanitization program and methods
Media SanitizationDedicated NZISM controlsClear / Purge / Destroy
VerificationRead-back verification is specifically addressedVerification and validation framework
Failed SanitizationDestruction requiredEscalation / different technique / destruction as appropriate
SSD/flashSpecific restrictions and destruction requirementsTechnology-specific sanitization considerations
DisposalDeclassification + disposal controlsSanitization/disposition framework

They are therefore not competing wiping algorithms.

NZISM is a broader New Zealand Government security framework containing specific media-management and sanitization controls.

26

NZISM vs IEEE 2883

IEEE 2883-2022 focuses on storage sanitization methods and technology-specific requirements.

NZISM provides the broader New Zealand Government information-security context and specifies controls for sanitization, destruction and disposal.

A practical workflow can therefore be:

  1. 01NZISM Security Requirement
  2. 02Storage Technology Assessment
  3. 03Applicable Technical Sanitization Method
  4. 04Execution
  5. 05Verification
  6. 06NZISM Documentation / Assurance

DSP can provide the operational sanitization component within this type of workflow.

27

NZISM For Government And High-Security Environments

NZISM is particularly relevant to:

  • New Zealand Government Agencies
  • Crown Entities
  • Government Contractors
  • Government IT Suppliers
  • Secure ITAD Providers
  • Data Centers
  • Enterprise Environments
  • Organizations Handling Classified Information

The NCSC states that NZISM is specifically intended for New Zealand Government agencies while also encouraging Crown entities, local government and private-sector organizations to use it.

28

Offline NZISM Data Sanitization

DSP can support offline sanitization workflows where internet connectivity is restricted or unavailable.

This can be useful for:

  • Government Environments
  • Air-Gapped Networks
  • Secure Facilities
  • Restricted Laboratories
  • Controlled ITAD Environments
  • Sensitive Enterprise Systems

The sanitization operation can be executed locally while maintaining device and verification information for reporting.

29

Audit-Ready NZISM Sanitization Certificate

DSP can generate an audit-ready sanitization certificate documenting the operation performed by DSP.

Device Information

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Interface
  • Media type

Sanitization Information

  • NZISM sanitization profile
  • Selected technique
  • Execution status
  • Start time
  • Completion time

Verification

  • Read-back verification
  • Verification result
  • Errors
  • Failed regions
  • Validation result

Operator & Audit

  • Operator
  • Workstation/system
  • Asset or case information where configured
  • Date/time
  • Audit metadata

Important Certification Clarification

The DSP certificate is evidence of the sanitization operation performed by DSP.

It is not an NCSC-issued NZISM certificate and DSP should not be marketed as “NZISM certified” unless a separate, independently established certification exists.

30

NZISM And Storage Reuse

NZISM's sanitization requirements are particularly relevant when media is:

  • Reused
  • Redeployed
  • Transferred
  • Reclassified
  • Disposed
  • Released From An Organization

The NCSC's current asset-lifecycle guidance also recommends sanitizing devices before reuse or repurposing.

DSP can provide the operational evidence required to show what sanitization method was executed and what verification result was obtained.

31

NZISM Sanitization In Data Sanitization Pro

NZISM-Specific Workflow

DSP provides a dedicated NZISM sanitization profile rather than treating NZISM as a generic overwrite preset.

Media-Aware Processing

The sanitization workflow can account for differences between magnetic, flash and other supported storage technologies.

Read-Back Verification

DSP can verify the completed sanitization operation.

Failure Detection

Failed sanitization can be identified and documented.

Bad-Sector Intelligence

Storage errors and inaccessible regions can be reported.

Device Health

SMART and storage-health information can accompany the sanitization record.

Offline Operation

Suitable for controlled environments without internet dependency.

Multi-Device Processing

Supported devices can be processed according to operational requirements.

Audit-Ready Reporting

Generate device-level documentation connecting the storage asset to its sanitization result.

NZISM — Sanitization Decision Model

The most accurate way to understand the NZISM approach is:

Can The Media Be Effectively Sanitized?

Yes

→ Apply the applicable sanitization method → Read back and verify → Validate → Document → Declassify/approve as required → Reuse or dispose

NO

→ Destroy the media → Document destruction → Follow declassification and disposal procedures

This is substantially different from a simple “run three passes and issue a certificate” model.

32

25 Sanitization Methods In One Platform

NZISM is one of the government-oriented sanitization frameworks supported through DSP.

The DSP Sanitization Engine can provide separate selectable profiles for modern and historical methodologies such as:

Each methodology remains a separate selectable DSP sanitization profile, with its applicable execution, verification and reporting workflow.

FAQ

NZISM Questions

What Is NZISM?

NZISM is the **New Zealand Information Security Manual**, maintained by the New Zealand National Cyber Security Centre. It provides information-security controls and guidance for New Zealand Government agencies.

Is NZISM A Data Wiping Algorithm?

No. NZISM is a broader information-security manual containing specific controls for media sanitization, destruction and disposal.

Does NZISM Specify One Fixed Number Of Overwrite Passes?

No. Its sanitization requirements vary according to media type, technology and security requirements.

Does NZISM Require Verification?

Yes. The current media-sanitization section specifically states that media should be read back to verify that an overwrite process completed successfully.

What Happens If NZISM Sanitization Fails?

The current NZISM states that if sanitization cannot be successfully completed, destruction will be necessary.

Does NZISM Allow Software Sanitization Of SSDs?

The current NZISM specifically identifies flash memory and solid-state/hybrid storage among media that must be destroyed where they cannot be effectively sanitized. Therefore, a generic software overwrite should not be marketed as automatically making every SSD or flash device NZISM-sanitized.

Is Factory Reset NZISM Sanitization?

No. NZISM explicitly states that factory reset or similar operations do not constitute media sanitization.

Does DSP Provide An NZISM Certificate?

DSP can generate an **audit-ready sanitization certificate documenting the operation performed by DSP**.

Is The DSP Certificate Issued By The New Zealand Government?

No. It is a DSP-generated record of the sanitization operation and verification result.

Can NZISM Be Used For ITAD?

Yes. NZISM contains controls covering media sanitization, destruction, declassification and disposal, making it directly relevant to secure IT asset retirement workflows.

NZISM — Secure Media Sanitization With Verifiable Evidence

Data Sanitization Pro runs all 25 standards offline and verifies the result.