<section title="13.6. Media and IT Equipment Disposal"><subsection title="Objective"><paragraph
    title="13.6.1."


><![CDATA[<p>Media and IT equipment is declassified and approved by the CISO, or delegate, for release before disposal into the public domain.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="13.6.2."


><![CDATA[<p>This section covers information relating to the disposal of media and IT equipment. Further information relating to the disposal of IT equipment can be found in <a title="Product sanitisation and disposal" href="http://nzism.gcsb.govt.nz/ism-document#Section-14585">Section 12.6 - Product Sanitisation and Disposal</a>.</p>]]></paragraph>
<paragraph
    title="13.6.3."


><![CDATA[<p>NZEO endorsed material requires additional protection at every level of classification.</p>]]></paragraph>
<paragraph
    title="13.6.4."


><![CDATA[<p>In general terms, media and IT equipment containing NZEO material should be sanitised and redeployed or sanitised and destroyed in accordance with the procedures in this section. Media and IT equipment that has contained NZEO material must not be disposed of, to e-recyclers or sold to any third party.</p>]]></paragraph>
<paragraph
    title="13.6.5."


><![CDATA[<p>Note the discussion in section <a title="Media and IT equipment sanitisation" href="http://nzism.gcsb.govt.nz/ism-document#Section-14810">13.4 - Media and IT equipment sanitisation</a>, on the challenges and difficulties in effectively sanitising media of all types.</p>]]></paragraph>
</block>
</subsection>
<subsection title="Rationale &amp; Controls"> <block title="Declassification prior to disposal"><paragraph
    title="13.6.6.R.01."

    tags="Technical,Classifying Media,Media Disposal,Media Management"


><![CDATA[<p>Prior to its disposal, media and IT equipment needs to be declassified to ensure that classified information is not accidentally released into the public domain.</p>]]></paragraph>
<paragraph
    title="13.6.6.C.01."

    tags="Technical,Classifying Media,Media Disposal,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="4385"
><![CDATA[<p>Agencies MUST declassify all media and IT equipment prior to disposing of it into the public domain.</p>]]></paragraph>
<paragraph
    title="13.6.6.C.02."

    tags="Technical,Classifying Media,Media Disposal,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="4386"
><![CDATA[<p>Media and IT equipment that cannot be effectively sanitised or declassified MUST be destroyed and not released into the public domain.</p>]]></paragraph>
</block>
<block title="Disposal procedures"><paragraph
    title="13.6.7.R.01."

    tags="Technical,Classifying Media,Media Disposal,Media Management"


><![CDATA[<p>The following diagram illustrates the mandated disposal process. Note declassification describes the entire process, including any reclassifications, approvals and documentation, before media and media waste can be released into the public domain.</p>]]></paragraph>
<paragraph
    title="13.6.7.C.01."

    tags="Technical,Classifying Media,Media Disposal,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="4389"
><![CDATA[<p>Agencies MUST document procedures for the disposal of media and IT equipment.</p>
<p><img class="leftAlone" title="" src="assets/NZISM/MediaDisposalProcessOutline.png" alt="Media Disposal Process Outline Diagram" width="734" height="1052"></p>]]></paragraph>
</block>
<block title="Declassifying media"><paragraph
    title="13.6.8.R.01."

    tags="Technical,Classifying Media,Media Disposal,Media Management"


><![CDATA[<p>The process of reclassifying, sanitising or destroying media does not provide sufficient assurance for media to be declassified and released into the public domain. In order to declassify media, formal administrative approval is required before releasing the media or waste into the public domain.</p>]]></paragraph>
<paragraph
    title="13.6.8.C.01."

    tags="Technical,Classifying Media,Media Disposal,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="4392"
><![CDATA[<p>Agencies declassifying media MUST ensure that:</p><ul>
<li>the reclassification of all classified information on the media has been approved by the originator, or the media has been appropriately sanitised or destroyed; and</li>
<li>formal approval is granted before the media is released into the public domain.</li>
</ul>]]></paragraph>
</block>
<block title="Disposal of media"><paragraph
    title="13.6.9.R.01."

    tags="Technical,Classifying Media,Media Disposal,Media Management"


><![CDATA[<p>Disposing of media in a manner that does not draw undue attention ensures that media that was previously classified is not subjected to additional scrutiny over that of regular waste. This can include the removal of labels, markings and serial numbers.</p>]]></paragraph>
<paragraph
    title="13.6.9.C.01."

    tags="Technical,Classifying Media,Media Disposal,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="4395"
><![CDATA[<p>Agencies MUST dispose of media in a manner that does not draw undue attention to its previous classification.</p>]]></paragraph>
</block>
<block title="New Zealand Eyes Only (NZEO) Materials"><paragraph
    title="13.6.10.R.01."

    tags="Technical,Media Destruction,Media Disposal,Media Management,Media Sanitisation"


><![CDATA[<p>NZEO endorsed material requires additional protection at every level of classification and creates a special case in the destruction and disposal process.</p>]]></paragraph>
<paragraph
    title="13.6.10.C.01."

    tags="Technical,Media Destruction,Media Disposal,Media Management,Media Sanitisation"


    classification="All Classifications"
    compliance="Must"
    cid="4398"
><![CDATA[<p>Media and IT equipment that has contained NZEO material MUST be sanitised and redeployed or sanitised and destroyed in accordance with the procedures in this chapter.</p>]]></paragraph>
<paragraph
    title="13.6.10.C.02."

    tags="Technical,Media Disposal,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="4399"
><![CDATA[<p>For disposal of all NZEO endorsed materials, an approved destruction facility MUST be used.</p>]]></paragraph>
<paragraph
    title="13.6.10.C.03."

    tags="Technical,Media Disposal,Media Management"


    classification="All Classifications"
    compliance="Must Not"
    cid="4400"
><![CDATA[<p>Media and IT equipment that has contained NZEO material MUST NOT be disposed of via e-recyclers or sold to any third party.</p>]]></paragraph>
</block>
<block title="Approved Secure Destruction Facilities"><paragraph
    title="13.6.11.R.01."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


><![CDATA[<p class="NormS13C6">An approved secure destruction facility may be agency-owned or a commercial facility.</p>]]></paragraph>
<paragraph
    title="13.6.11.R.02."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


><![CDATA[<p class="NormS13C6">A number of regulatory and legislative requirements including those relating to health, safety, environmental protection, hazardous materials handling disposal and export, will have to be met by any such facility.</p>]]></paragraph>
<paragraph
    title="13.6.11.R.03."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


><![CDATA[<p class="NormS13C6">It may not be economically viable for individual agencies to own and maintain such facilities.  In such cases the use of a commercial facility may be the only practical alternative.</p>]]></paragraph>
<paragraph
    title="13.6.11.R.04."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


><![CDATA[<p class="NormS13C6">To ensure secure destruction facilities have the capability, capacity and equipment to securely destroy media and IT equipment to the specifications detailed in the NZISM, a formal approval is required.  An inspection of the facility and any necessary testing of the equipment will determine suitability for operation as a secure destruction facility.  If the results of the inspection and testing are satisfactory, a formal approval is issued.  Periodic re-inspections are conducted to ensure on-going compliance with the NZISM requirements.</p>]]></paragraph>
<paragraph
    title="13.6.11.R.05."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


><![CDATA[<p class="NormS13C6"><a title="Approved Secure Destruction Facilities - Guidance to Vendors" rel="noopener noreferrer" href="https://ncsc.govt.nz/assets/NCSC-Documents/ASDF-Info-For-Service-Providers.pdf" target="_blank">Commercial organisations may apply</a> to the GCSB for approval as a secure destruction facility under the NZISM.</p>]]></paragraph>
<paragraph
    title="13.6.11.R.06."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


><![CDATA[<p class="NormS13C6">The Director-General of the GCSB will issue such approvals if satisfied that the standards detailed in the NZISM have been satisfactorily been met and can be maintained. </p>]]></paragraph>
<paragraph
    title="13.6.11.C.01."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="5711"
><![CDATA[<p class="NormS13C6">Where agencies establish their own disposal/destruction facilities, these facilities MUST be approved by the Director-General GCSB.</p>]]></paragraph>
</block>
<block title="Use of Approved Secure Destruction Facilities"><paragraph
    title="13.6.12.R.01."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


><![CDATA[<p class="NormS13C6">Agencies may not have the facilities to securely dispose of media and IT equipment to the specifications detailed in the NZISM (Refer to <a title="Media and IT Equipment Destruction" href="http://nzism.gcsb.govt.nz/ism-document#Paragraph-14902">13.5.7 Media and IT Equipment Destruction</a> and <a title="Storage and handling of media waste particles" href="http://nzism.gcsb.govt.nz/ism-document#Paragraph-14904">13.5.9 Storage and handling of media waste particles</a>).&nbsp; In these circumstances the use of an <a title="ASDFs" rel="noopener noreferrer" href="https://www.gcsb.govt.nz/our-work/national-cyber-security-centre-ncsc/approved-secure-destruction-facilities/" target="_blank">approved secure disposal or destruction facility</a> (agency owned or a commercial facility) is permitted <span style="text-decoration: underline;">provided</span> all other procedures in this Chapter are followed.</p>]]></paragraph>
<paragraph
    title="13.6.12.R.02."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


><![CDATA[<p class="NormS13C6">The GCSB maintains a register of <a title="ASDFs" rel="noopener noreferrer" href="https://www.gcsb.govt.nz/our-work/national-cyber-security-centre-ncsc/approved-secure-destruction-facilities/" target="_blank">approved secure disposal/destruction facilities</a>.</p>]]></paragraph>
<paragraph
    title="13.6.12.R.03."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


><![CDATA[<p class="NormS13C6">In practical terms this requires tracking, supervision and oversight (witnessed) to the point where the disposal/destruction process is complete.&nbsp; Procedures are detailed in <a title="Media and IT Equipment Destruction" href="http://nzism.gcsb.govt.nz/ism-document#Section-14890">Section 13.5 - Media and IT Equipment Destruction</a>.</p>]]></paragraph>
<paragraph
    title="13.6.12.C.01."

    tags="Technical,Media Destruction,Media Disposal,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="5716"
><![CDATA[<p class="NormS13C6">&nbsp;Agencies MUST use an <a title="ASDFs" rel="noopener noreferrer" href="https://www.gcsb.govt.nz/our-work/national-cyber-security-centre-ncsc/approved-secure-destruction-facilities/" target="_blank">approved secure disposal/destruction facility</a> for the destruction of media and IT equipment.</p>]]></paragraph>
</block>
</subsection>
</section>
