<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISSP Question Clarification regarding media sanitization. in Exams</title>
    <link>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/47649#M1779</link>
    <description>&lt;P&gt;.... clearing for reuse in a lower-security area &lt;STRONG&gt;than it was formerly used in&lt;/STRONG&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The comment is about the "change in classification" for the media; not about the continuing use in a lesser classification.&lt;/P&gt;</description>
    <pubDate>Sun, 26 Sep 2021 03:45:40 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2021-09-26T03:45:40Z</dc:date>
    <item>
      <title>CISSP Question Clarification regarding media sanitization.</title>
      <link>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/47648#M1778</link>
      <description>&lt;P&gt;&lt;EM&gt;Q. Megan wants to prepare media to allow for its reuse in an environment operating at the same sensitivity level. Which of the following is the best option to meet her needs? Clearing Erasing Purging Sanitization&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Answer as per the Official Study Guide -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Clearing describes preparing media for reuse. When media is cleared, unclassified data is written over all addressable locations on the media. Once that's completed, the media can be reused. Purging is a more intensive form of clearing for reuse in lower-security areas.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, since purging is a more intensive form of clearing then why is it used for reuse in lower-security areas. I thought the answer to this question should have been purging. So in which instances should clearing and purging be used?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Sep 2021 14:28:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/47648#M1778</guid>
      <dc:creator>arkahnz</dc:creator>
      <dc:date>2021-09-25T14:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Question Clarification regarding media sanitization.</title>
      <link>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/47649#M1779</link>
      <description>&lt;P&gt;.... clearing for reuse in a lower-security area &lt;STRONG&gt;than it was formerly used in&lt;/STRONG&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The comment is about the "change in classification" for the media; not about the continuing use in a lesser classification.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Sep 2021 03:45:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/47649#M1779</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2021-09-26T03:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Question Clarification regarding media sanitization.</title>
      <link>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/47651#M1781</link>
      <description>&lt;P&gt;If you were to clear the data from media used in a highly classified area and then reuse the media in a lower classified area, there is a risk of writing data down; therefore it should be purged to treat that risk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 07:14:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/47651#M1781</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2021-09-27T07:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Question Clarification regarding media sanitization.</title>
      <link>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/47674#M1784</link>
      <description>Thanks for clarifying.</description>
      <pubDate>Wed, 29 Sep 2021 06:32:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/47674#M1784</guid>
      <dc:creator>arkahnz</dc:creator>
      <dc:date>2021-09-29T06:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Question Clarification regarding media sanitization.</title>
      <link>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/50251#M1891</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Arkhanz,&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Replies for the CISSP question about reuse of media and what method for same level of sensitivity and your question about differences of clearing and purging in this context and use.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;It's clearing and not purging for environment/department of same level of sensitivity.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The CISSP question indicates that Megan wants to&amp;nbsp;&lt;EM&gt;reuse the media in an environment operating at the SAME sensitivity level. Then, clearing the media would be the best approach since it would be reused with the same classification level and not require purging. (This is cited in NIST&amp;nbsp;Special Publication 800-88.)&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;EM&gt;You are correct about purging being more intensive than clearing, but it is reasonable that the clearing process within the same sensitivity area, so the most efficient and cost-effective control would be clearing. (You mentioned lower-security area, and it may well be, but the question posed does not clarify that, just that it is the same sensitivity area.)&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;SPAN&gt;&amp;nbsp;You ask in which instances should clearing and purging be used? When the media is within the confines of an area, environment, department - then clearing would be appropriate. When the media is to leave the environment and will not be reused but instead destroyed, then the data on the disk should be completely over-writtten&amp;nbsp; by degaussing (magnetic erasing) or firmware&amp;nbsp;commands (and tools)which would lead data to be unrecoverable with a high level of confidence. Note, that once degaussed, the disk data and startup files are removed, making the disk unusable, thus this would not be the answer to the CISSP example question.&amp;nbsp;&lt;BR /&gt;Hope this is helpful to you and others.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 15:32:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/50251#M1891</guid>
      <dc:creator>YBaker</dc:creator>
      <dc:date>2022-03-23T15:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: CISSP Question Clarification regarding media sanitization.</title>
      <link>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/64718#M2810</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="photo_2023-11-20_16-50-15.jpg" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/7944i54C2094141EE2A88/image-size/large?v=v2&amp;amp;px=999" role="button" title="photo_2023-11-20_16-50-15.jpg" alt="photo_2023-11-20_16-50-15.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (292).png" style="width: 900px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/7945iB4F3F9B3BFF7EDCC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (292).png" alt="Screenshot (292).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See both the above photos. Both are from NIST SP 800-88, where it's clear that the media can be reused in clearing as well as purging.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also within org control for high-sec sec data, there is only one option, which is purge or destroy there is no clear option in the flow chart as per NIST.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if you go with NIST then it should be purging and not clearing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anything else am missing?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 11:25:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exams/CISSP-Question-Clarification-regarding-media-sanitization/m-p/64718#M2810</guid>
      <dc:creator>Anto</dc:creator>
      <dc:date>2023-11-20T11:25:41Z</dc:date>
    </item>
  </channel>
</rss>

