Data Dumps: Safe Disposal of Storage Devices
Removable data storage devices like CDs, DVDs, and flash drives offer workers an easy way to transfer information between computers or colleagues. But employees may not be the only ones accessing their contents. If not managed properly, these disposable devices can be a prime target for data theft.
Safe Storage
Removable storage devices often contain sensitive personal and company data, so organizations should develop a policy for employees to help prevent unauthorized access in case of a lost or stolen drive. Such guidelines may include instructing workers to:
• Always use encryption or passwords on their device to prevent unauthorized access.
• Limit the type of data they place on a device.
• Delete data once they no longer need it.
• Report any missing device immediately.
Gone But Not Forgotten
When it’s time to dispose of an unwanted or defective storage device, employees may believe that simply deleting the files contained within is enough to wipe the device clean. But that’s not the case. Much of the data can still be recovered with a data recovery program.
Instead, organizations should advise workers to take the following steps:
1. Identify and back up any necessary company data elsewhere.
2. Securely remove all files from the storage device using a company-approved data removal tool that either wipes the device clean or overwrites it with random data.
3. Either return the device to the company or physically destroy it so that no data can be recovered. For a flash drive, that means smashing the circuit board and chips and tossing them. For CDs and DVDs, employees can simply cut them into pieces or shred them.
A Clean Slate
Removable storage devices aren’t just convenient for workers, but also for cyber criminals who want to breach these devices to access valuable data. To help your organization teach employees the best way to manage CDs, DVDs, and flash drives at the end of their useful life.
The safest practice is to offer thorough, sound educational courses enterprise-wide.