Educause Security Discussion mailing list archives

Re: HazMat/Disposition


From: Doug Markiewicz <dmarkiew+educause () ANDREW CMU EDU>
Date: Tue, 8 Sep 2009 08:04:28 -0400

What is everyone doing for disposal of computing/networking/peripherals?

We dispose of computing equipment through our Environmental Health and
Safety department.  They were originally responsible for disposing of CRTs
and eventually expanded those services to include storage media.


Do you have HazMat regulatory requirements/procedures?

Any procedures of this nature are maintained by our Environmental Health and
Safety department.


How about data classification - are some devices more sensitive than
others which require a signature/2nd signature before disposal?

We do have a data classification scheme and we publish guidance on disposal
of storage media that references that classification scheme.  Our disposal
guidance is largely based on NIST SP 800-88 Guidelines for Media
Sanitization.  Our Environmental Health and Safety department contracts with
a third-party to dispose of equipment.  Storage media is destroyed and a
destruction certificate is made available to us.  We don't have much in the
way of checks to ensure storage media has been authorized for destruction.
We leave this for individual business units to manage.

Hope this is helpful.

Current thread: