CAS-001 · Question #23
An Information Security Officer (ISO) has asked a security team to randomly retrieve discarded computers from the warehouse dumpster. The security team was able to retrieve two older computers and a…
The correct answer is D. Update the hardware decommissioning procedures. Sensitive data was recoverable from a discarded printer's hard drive, indicating that the organization's hardware disposal process failed to include proper data sanitization before physical disposal.
Question
An Information Security Officer (ISO) has asked a security team to randomly retrieve discarded computers from the warehouse dumpster. The security team was able to retrieve two older computers and a broken MFD network printer. The security team was able to connect the hard drives from the two computers and the network printer to a computer equipped with forensic tools. The security team was able to retrieve PDF files from the network printer hard drive but the data on the two older hard drives was inaccessible. Which of the following should the Warehouse Manager do to remediate the security issue?
Options
- ARevise the hardware and software maintenance contract.
- BDegauss the printer hard drive to delete data.
- CImplement a new change control process.
- DUpdate the hardware decommissioning procedures.
How the community answered
(47 responses)- A2% (1)
- C4% (2)
- D94% (44)
Why each option
Sensitive data was recoverable from a discarded printer's hard drive, indicating that the organization's hardware disposal process failed to include proper data sanitization before physical disposal.
A hardware and software maintenance contract governs ongoing support and repairs, not end-of-life data sanitization practices during disposal.
Degaussing the printer hard drive after the fact is a reactive remediation of one device, not a systemic fix that prevents the same issue with future hardware disposals.
A change control process governs modifications to systems and configurations, not the secure decommissioning and disposal of retired hardware assets.
Updating hardware decommissioning procedures directly addresses the root cause - the warehouse was disposing of devices containing readable data without first sanitizing storage media, so formalizing a process that mandates data wiping, degaussing, or physical destruction before disposal prevents future data exposure.
Concept tested: Secure hardware decommissioning and data sanitization
Source: https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.