Data remanence

Data remanence is the residual representation of data that remains even after attempts have been made to remove or erase the data. This residue may result from data being left intact by a nominal file deletion operation, by reformatting of storage media that does not remove data previously written to the media, or through physical [...]

Causes

Many operating systems, file managers, and other software provide a facility where a file is not immediately deleted when the user requests that action. Instead, the file is moved to a holding area, to allow the user to easily revert a mistake. Similarly, many software products automatically create backup copies of files that are being [...]

Countermeasures

There are three levels commonly recognized for eliminating remnant data: ,Clearing Clearing is the removal of sensitive data from storage devices in such a way that there is assurance that the data may not be reconstructed using normal system functions or software file/data recovery utilities. The data may still be recoverable, but not without special [...]

Specific methods

Overwriting A common method used to counter data remanence is to overwrite the storage medium with new data. This is often called wiping or shredding a file or disk. Because such methods can often be implemented in software alone, and may be able to selectively target only part of a medium, it is a popular, [...]

Complications

Inaccessible media areas Storage media may have areas which become inaccessible by normal means. For example, magnetic disks may develop new “bad sectors” after data have been written, and tapes require inter-record gaps. Modern hard disks often feature automatic remapping of marginal sectors or tracks, which the OS may not even be aware of. This [...]

Standards

Australia * DSD ISM 2010: Australian Government Information Security Manual, Nov 2010 [9] Canada * RCMP B2-002: IT Media Overwrite and Secure Erase Products, May 2009 [10] * Communications Security Establishment Clearing and Declassifying Electronic Data Storage Devices, July 2006 [11] New Zealand * GCSB NZISM 2010: New Zealand Information Security Manual, Dec 2010 [12] [...]