CertifiedNIST SP 800-88 Rev. 2 · DoD 5220.22-M · IEEE 2883

Standard 25 Of 25 · Government And Defence

RCMP TSSIT OPS-II Canadian — Secure Data Erasure & Data Sanitization Software

Canadian RCMP TSSIT OPS-II Data Erasure Method

Canada7 PassesVerification Required
Canadian public sector drives erased with RCMP OPS-II

At A Glance

Published By
Royal Canadian Mounted Police
Reference
Technical Security Standard for Information Technology, Appendix OPS-II
Region
Canada
Passes
7
Verification
Required By The Standard, Locked On
Relative Run Time
8× a single pass

What The Software Writes

  1. Pass 1 Fixed pattern 0x00
  2. Pass 2 Fixed pattern 0xFF
  3. Pass 3 Fixed pattern 0x00
  4. Pass 4 Fixed pattern 0xFF
  5. Pass 5 Fixed pattern 0x00
  6. Pass 6 Fixed pattern 0xFF
  7. Pass 7 Random data
  8. Verify Required by the standard. Every sector is read back and compared.
  9. Certify Signed certificate with device, method, result and operator

RCMP TSSIT OPS-II is a historical Canadian media sanitization and secure data erasure methodology associated with the Royal Canadian Mounted Police (RCMP). It is widely recognized in data wiping software as a structured multi-pass overwrite profile designed primarily for magnetic storage media.

The method is commonly represented as a seven-pass overwrite sequence, using alternating binary patterns followed by a final random-data pass and verification.

For organizations that specifically require the historical RCMP TSSIT OPS-II methodology, Data Sanitization Pro (DSP) provides a dedicated RCMP TSSIT OPS-II Sanitization Method through the DSP Sanitization Engine, with execution monitoring, verification and audit-ready documentation.

Important: RCMP TSSIT OPS-II should not be represented as the current Government of Canada media-sanitization standard. Canada's current federal IT-media sanitization guidance is issued through the Communications Security Establishment (CSE), including ITSP.40.006 v2 – IT Media Sanitization.

01

What Is RCMP TSSIT OPS-II?

RCMP TSSIT OPS-II is a historical Canadian secure data wiping profile designed around repeated overwriting of addressable storage locations.

The commonly implemented sequence is:

PassData Pattern
Pass 10x00
Pass 20xFF
Pass 30x00
Pass 40xFF
Pass 50x00
Pass 60xFF
Pass 7Random data
VerificationVerify the completed sanitization

The exact implementation of historical RCMP TSSIT OPS-II profiles can vary between software products. DSP should therefore document the actual method configuration executed, rather than treating the name alone as proof of a particular implementation.

The seven-pass profile is primarily associated with conventional magnetic storage and historical secure overwriting practices.

02

Historical Canadian Sanitization Method

RCMP TSSIT OPS-II belongs to an earlier generation of software-based media sanitization methods that relied heavily on repeated overwriting.

Its fundamental concept is straightforward:

  1. 01Write
  2. 02Rewrite
  3. 03Rewrite
  4. 04Rewrite
  5. 05Rewrite
  6. 06Rewrite
  7. 07Randomize
  8. 08Verify

The method was designed around the principle that repeated alteration of the storage surface would reduce the ability to reconstruct previously stored information.

Today, storage technology has evolved substantially. Modern SSDs, NVMe drives and flash media use controllers, wear leveling, spare areas and other mechanisms that can make conventional multi-pass overwriting unsuitable as a universal sanitization strategy.

Consequently, the RCMP TSSIT OPS-II method should be selected based on the storage technologyorganizational policy, sensitivity of information and intended disposition of the media.

03

RCMP TSSIT OPS-II In Data Sanitization Pro

DSP includes a dedicated RCMP TSSIT OPS-II Sanitization Method within the DSP Sanitization Engine.

04

DSP Workflow

SELECT RCMP TSSIT OPS-II ↓ IDENTIFY STORAGE DEVICE ↓ ASSESS MEDIA TYPE & HEALTH ↓ EXECUTE 7-PASS SANITIZATION ↓ MONITOR WRITE PROCESS ↓ VERIFY RESULT ↓ DOCUMENT OPERATION ↓ GENERATE AUDIT-READY CERTIFICATE

The selected method is executed as a defined DSP sanitization operation rather than simply providing a generic overwrite function.

05

Seven-Pass RCMP TSSIT OPS-II Process

06

Pass 1 — Zero Pattern

The target addressable storage area is overwritten with a zero-value pattern:

07

0x00

08

Pass 2 — One Pattern

The storage area is overwritten with:

09

0xFF

01

Pass 3 — Zero Pattern

The zero pattern is written again.

02

Pass 4 — One Pattern

The 0xFF pattern is written again.

03

Pass 5 — Zero Pattern

The zero pattern is repeated.

04

Pass 6 — One Pattern

The 0xFF pattern is repeated.

05

Pass 7 — Random Data

The final overwrite uses random data.

06

Verification

The completed operation is checked according to the configured verification procedure.

This structure is the commonly documented RCMP TSSIT OPS-II seven-pass profile. Commercial software implementations may differ in their exact treatment of patterns and verification, so the DSP certificate should identify the actual operation performed.

10

RCMP TSSIT OPS-II For HDD Data Erasure

RCMP TSSIT OPS-II is most naturally associated with traditional magnetic hard disk drives.

DSP can use the method for applicable HDD sanitization workflows while simultaneously recording device information such as:

  • Manufacturer
  • Model
  • Serial Number
  • Capacity
  • Interface
  • Firmware Information
  • Device Health
  • SMART Information
  • Power-On Information Where Available
  • Sector/read Errors
  • Bad-Sector Information
  • Sanitization Method
  • Start And Completion Timestamps
  • Verification Result
  • Operator Information

This creates a detailed operational record around the historical wiping methodology.

11

SSD, NVMe And Flash Storage Considerations

A seven-pass overwrite profile should not automatically be treated as equivalent to complete physical sanitization of modern flash storage.

SSDs and NVMe devices can contain:

  • Flash Translation Layers (FTL)
  • Wear-Leveling Mechanisms
  • Over-Provisioned Areas
  • Spare Blocks
  • Remapped Blocks
  • Garbage-Collection Areas
  • Controller-Managed Storage Locations

A conventional host-level overwrite may therefore not provide equivalent coverage of every physical flash location.

For this reason, RCMP TSSIT OPS-II should be treated as a method-specific historical overwrite profile, not a universal sanitization technique for every modern storage architecture.

For modern SSD/NVMe sanitization, the applicable device capabilities and organizational requirements should be assessed before selecting the sanitization technique.

Current Canadian federal guidance recognizes multiple sanitization approaches, including overwriting, Secure Erase (SE), Cryptographic Erase (CE)anddestruction, depending on media type and sensitivity.

12

Device Health And Bad-Sector Intelligence

Successful completion of a wiping operation does not automatically mean that every physical storage location was successfully sanitized.

DSP can assess storage conditions before and during sanitization, including:

SMART / Device Health

  • Overall health
  • Temperature
  • Power-on hours
  • Device errors
  • Firmware information
  • Performance indicators

Bad-Sector Assessment

  • Logical bad sectors
  • Physical/read errors
  • Unreadable areas
  • Reallocated sectors
  • Sanitization failures
  • Verification anomalies

If portions of a device cannot be reliably addressed or verified, the sanitization result should be evaluated against the organization's media-disposition requirements.

This is particularly important for damaged HDDs, SSDs and flash storage where unsuccessful sanitization may require a stronger disposal or destruction procedure.

13

Verification After Sanitization

Verification is a critical part of a professional data erasure workflow.

DSP records the result of the sanitization operation and can identify:

  • Completed Passes
  • Write Status
  • Errors
  • Verification Status
  • Failed Sectors
  • Device Condition
  • Start/end Time
  • Operator
  • Selected Sanitization Method

The purpose is to distinguish between:

14

“A Wiping Process Was Started”

and

15

“The Selected Sanitization Operation Was Completed And Its Result Was Verified And Documented.”

Canadian federal IT-media guidance emphasizes verification of sanitization results and recognizes that media which cannot be satisfactorily sanitized or verified may require additional handling or destruction depending on sensitivity.

16

RCMP TSSIT OPS-II And Current Canadian Guidance

RCMP TSSIT OPS-II should be understood as a historical Canadian overwrite methodology.

The current Government of Canada IT-media sanitization framework is ITSP.40.006 v2, issued under the authority of the Chief of the Communications Security Establishment. It provides a broader risk-based approach to media sanitization rather than prescribing one universal seven-pass overwrite method.

Current Canadian guidance recognizes:

  • Overwriting
  • Secure Erase
  • Cryptographic Erase
  • Degaussing For Applicable Magnetic Media
  • Physical Destruction Where Required
  • Verification
  • Media-Specific Sanitization
  • Data Sensitivity
  • Reuse And Disposal Requirements

It also recognizes that modern media can be more difficult to reliably sanitize and that encryption can facilitate lifecycle sanitization.

17

RCMP TSSIT OPS-II vs Modern Canadian ITSP.40.006

AreaRCMP TSSIT OPS-IIITSP.40.006 V2
OriginHistorical Canadian RCMP methodologyCurrent CSE guidance
ApproachDefined overwrite profileRisk- and media-based sanitization
Typical Historical Profile7-pass overwriteMultiple applicable techniques
HDDPrimarily applicableApplicable with media-specific assessment
SSD/NVMeConventional overwrite limitationsDevice-appropriate methods
Secure EraseNot the core methodSupported where applicable
Cryptographic EraseNot the core methodSupported
DestructionSeparate considerationIncluded where sanitization is insufficient
VerificationMethod verificationVerification is part of sanitization
Modern ApplicabilityHistorical/method-specificCurrent Canadian federal guidance
18

RCMP TSSIT OPS-II vs DoD 5220.22-M

RCMP TSSIT OPS-II and DoD 5220.22-M are often grouped together because both are historical multi-pass overwrite methodologies.

However, their historical pattern sequences are different.

MethodCommonly Represented Profile
RCMP TSSIT OPS-II00 → FF → 00 → FF → 00 → FF → Random
DoD 5220.22-MHistorical multi-pass DoD overwrite profile
HMG IS5 EnhancedHistorical UK multi-pass profile
GutmannHistorical 35-pass methodology
SchneierHistorical 7-pass methodology

The number of passes alone should not be used as a universal measure of sanitization strength. Media architecture, addressability, sanitization technique, verification and disposition requirements are also relevant.

19

RCMP TSSIT OPS-II For ITAD And Enterprise Data Erasure

Historical overwrite methods continue to appear in:

  • IT Asset Disposition (ITAD)
  • Data Destruction Workflows
  • Refurbishment Operations
  • Hardware Resale
  • Enterprise IT Recycling
  • Data Center Decommissioning
  • Secure Equipment Disposal
  • Legacy Compliance Procedures
  • Contractual Sanitization Requirements

For organizations whose internal procedure specifically calls for RCMP TSSIT OPS-II, DSP can provide a dedicated method, execution tracking and audit-ready documentation.

For modern media organizations should select the appropriate sanitization technique based on their current security policy and media architecture.

20

Offline Data Sanitization

DSP can support controlled offline sanitization environments where devices must be processed without Internet connectivity.

This is useful for environments such as:

  • Government
  • Defense
  • Law Enforcement
  • Data Centers
  • ITAD Facilities
  • Secure Refurbishment
  • Enterprise Disposal Centers
  • Restricted Laboratories

The sanitization operation can be performed locally while maintaining method, device and verification records.

21

Multi-Device Sanitization

For professional ITAD and enterprise environments, DSP can process multiple supported storage devices while maintaining individual device-level records.

Each device can retain its own:

  1. 01Device Identity
  2. 02Selected Method
  3. 03Sanitization Progress
  4. 04Verification
  5. 05Result
  6. 06Certificate

This makes the RCMP TSSIT OPS-II workflow suitable for controlled batch-processing environments where individual device traceability is required.

22

Audit-Ready RCMP TSSIT OPS-II Certificate

After the sanitization operation, DSP can generate an audit-ready sanitization certificate documenting the actual operation performed by the software.

Certificate information can include:

Device Information

  • Manufacturer
  • Model
  • Serial number
  • Capacity
  • Media/interface type

Sanitization Information

  • RCMP TSSIT OPS-II
  • Configured pass sequence
  • Start time
  • Completion time
  • Sanitization status

Verification Information

  • Verification status
  • Errors
  • Failed areas
  • Device health observations

Operator & System Information

  • Operator
  • Workstation/system
  • Software version
  • Date/time
  • Audit metadata

Result

Sanitization Completed — Verified — Documented

The certificate is evidence of the sanitization operation performed by DSP. It is not an RCMP-issued certificate, Government of Canada certificationorendorsement by the RCMP.

23

DSP Sanitization Method — RCMP TSSIT OPS-II

DSP's implementation provides a controlled workflow around the historical methodology:

IDENTIFY Identify the target storage device.

CLASSIFY Determine media type and relevant device characteristics.

ASSESS Evaluate health, accessibility, errors and addressable storage.

SELECT Select RCMP TSSIT OPS-II.

EXECUTE Run the configured seven-pass sanitization process.

VERIFY Check the operation and recorded results.

VALIDATE Determine whether the result satisfies the applicable organizational requirement.

DOCUMENT Record device, method, operator and verification information.

CERTIFY Generate an audit-ready sanitization certificate documenting the operation.

24

Why Use A Dedicated RCMP TSSIT OPS-II Method?

A dedicated method is useful when an organization's procedure, contract or legacy asset-disposal workflow specifically identifies RCMP TSSIT OPS-II.

DSP provides:

  • Dedicated RCMP TSSIT OPS-II Method
  • Defined Seven-Pass Workflow
  • Device Identification
  • Sanitization Progress Monitoring
  • Verification
  • SMART/device-Health Information
  • Bad-Sector Reporting
  • Error Tracking
  • Offline Operation
  • Multi-Device Processing
  • Audit-Ready Reporting
  • PDF/HTML Reporting
  • Operator And System Traceability

The method can therefore be selected as a documented sanitization profile rather than relying on an unspecified generic disk wipe.

25

RCMP TSSIT OPS-II In Modern Data Erasure

The historical seven-pass approach remains relevant where a documented legacy method must be reproduced.

However, modern storage sanitization requires technology awareness.

For:

HDD Traditional overwrite techniques can be applicable when the entire addressable area can be reliably written and verified.

SSD / NVMe Device-specific sanitization capabilities, Secure Erase, Cryptographic Erase or other approved techniques may be more appropriate depending on the device and security requirement.

Flash / USB / Memory Media Controller behavior, spare cells and wear leveling must be considered.

Damaged Media If complete sanitization and verification cannot be achieved, the appropriate organizational disposal policy may require controlled destruction.

This media-specific approach is consistent with current Canadian federal guidance, which distinguishes sanitization techniques according to media type and sensitivity.

26

RCMP TSSIT OPS-II — Historical Method, Modern Documentation

RCMP TSSIT OPS-II represents an important historical Canadian approach to secure data wiping.

DSP preserves that methodology as a dedicated, documented sanitization method for organizations that specifically require it, while providing modern operational capabilities around device identification, monitoring, verification and reporting.

RCMP TSSIT OPS-II Seven-Pass Canadian Data Erasure Method Executed through the DSP Sanitization Engine Verified and Documented with an Audit-Ready Sanitization Certificate

FAQ

RCMP OPS-II Questions

Is RCMP TSSIT OPS-II Still The Current Canadian Government Data Sanitization Standard?

No. It should be treated as a historical RCMP overwrite methodology. Current Government of Canada IT-media sanitization guidance is provided through CSE's **ITSP.40.006 v2 – IT Media Sanitization**.

How Many Passes Does RCMP TSSIT OPS-II Use?

The commonly documented profile uses **seven passes**: alternating 0x00 and 0xFF patterns for the first six passes, followed by random data on the seventh pass and verification.

Is RCMP TSSIT OPS-II Suitable For SSDs?

A conventional multi-pass overwrite should not automatically be treated as complete sanitization of SSD or NVMe physical storage because flash devices use controller-managed architectures such as wear leveling and spare areas.

Does DSP Provide An RCMP TSSIT OPS-II Certificate?

DSP can generate an audit-ready certificate documenting the RCMP TSSIT OPS-II operation actually performed by DSP. This is **not an RCMP or Government of Canada-issued certificate**.

Is RCMP TSSIT OPS-II The Same As DoD 5220.22-M?

No. Both are historical multi-pass wiping methodologies, but their documented overwrite profiles differ.

Can RCMP TSSIT OPS-II Be Used For ITAD?

Yes, where the organization's documented sanitization procedure specifically requires the historical method and the target media is appropriate for the technique.

What Happens If A Device Cannot Be Completely Sanitized?

The result should be assessed against the applicable security and disposition policy. Current Canadian guidance recognizes that media that cannot be adequately sanitized or verified may require destruction or additional controls depending on information sensitivity.

Run RCMP OPS-II With A Certificate For Every Drive

Data Sanitization Pro runs all 25 standards offline and verifies the result.