A Guide to Understanding Data Remanence in Automated Information Systems


Table of Contents


NCSC-TG-025

Library No. 5-236,082

Version-2

FOREWORD

The National Computer Security Center is issuing A Guide to Understanding Data Remanence in Automated Information Systems as part of the "Rainbow Series" of documents our Technical Guidelines Program produces. In the Rainbow Series, we discuss in detail the features of the Department of Defense Trusted Computer System Evaluation Criteria (DoD 5200.28-STD) and provide guidance for meeting each requirement. The National Computer Security Center, through its Trusted Product Evaluation Program, evaluates the security features of commercially-produced computer systems. Together, these programs ensure that organizations are capable of protecting their important data with trusted computer systems. While data remanence is not a directly evaluated criterion of trusted computing systems, it is an issue critical to the safeguarding of information used by trusted computing systems.

A Guide to Understanding Data Remanence in Automated Information Systems is intended for use by personnel responsible for the secure handling of sensitive or classified automated information system memory and secondary storage media. It is important that they be aware of the retentive properties of such media, the known risks in attempting to erase and release it, and the approved security procedures that will help prevent disclosure of sensitive or classified information. This version supersedes CSC-STD-005-85, Department of Defense Magnetic Remanence Security Guideline, dated 15 November 1985.

As the Director, National Computer Security Center, I invite your suggestions for revising this document. We plan to review this document as the need arises.

Patrick R. Gallagher, JR September 1991

Director

National Computer Security Center

ACKNOWLEDGMENTS

The National Computer Security Center extends recognition to Captain James K. Goldston, United States Air Force, for providing engineering support and as primary author and preparer of this guideline. We thank the many people involved in preparing this document. Their careful review and input were invaluable. The National Computer Security Center extends recognition to Dr. Bane W. Burnham and David N. Kreft, without whom this revision could not have taken place. Other reviewers that provided much needed input are Carole S. Jordan, Lawrence M. Sudduth, and Kim Johnson-Braun and George L. Cipra.

1 INTRODUCTION

Data remanence is the residual physical representation of data that has been in some way erased. After storage media is erased there may be some physical characteristics that allow data to be reconstructed. This document discusses the role data remanence plays when storage media is erased for the purposes of reuse or release.

Various documents have been published that detail procedures for clearing, purging, declassifying, or destroying automated information system (AIS) storage media. [1,2,4, 5, 6, 8,9,13 and 16] The Department of Defense (DoD) published DoD Directive 5200.28, Security Requirements for Automated Information Systems, [17] and its corresponding security manual DoD 5200.28-M, Automated Data Processing Security Manual, [1] in 1972 and 1973, respectively. These two documents were amended in 1979, in response to the Defense Science Board Task Force recommendation to establish uniform DoD policy for computer security requirements, controls, and measures. The directive was again revised in March 1988, and efforts are underway to revise the manual.

DoD 5200.28-M addresses DoD requirements for the secure handling and disposal of memory and secondary storage media. While the Department of Defense requires the use of DoD Directive 5200.28 and DoD 5200.28-M by DoD components, the heads of DoD components may augment these requirements to meet their needs by prescribing more detailed guidelines and instructions provided they are consistent with these policies. DoD contractors and subcontractors who participate in the Defense Industrial Security Program (DISP) are required to comply with DoD 5220.22-M, Industrial Security Manual for Safeguarding Classified Information. [8] The Defense Investigative Service is responsible for the promulgation of the policy reflected in DoD 5220.22-M. Unlike these policy documents, A Guide To Understanding Data Remanence In Automated Information Systems does not provide requirements.

Sometime during the life cycle of an AIS, its primary and secondary storage may need to be reused, declassified, destroyed, or released. It is important that security officers, computer operators, and other users or guardians of AS resources be informed of the risks involving the reuse, declassification, destruction, and release of AIS storage media. They also should be knowledgeable of the risks inherent in changing the sensitivity level of AS storage media or of moving media from an installation with a specific security posture tone that is less secure. They should use proper procedures to prevent a possible disclosure of sensitive information contained on such media. ("Sensitive" in this document refers to classified and sensitive but unclassified information.) The procedures and guidelines in this document are based on research, investigation, current policy, and standard practice.

This guideline is divided as follows: Section 2 provides information on using this guideline and introduces DoD terminology. Section 3 discusses the use of degaussers and references the Degausser Products List (DPL), a listing of DoD evaluated degaussers. Section 4, "Risk Considerations," has information similar to that found in version 1 of this document, except for the modification of Section 4.2, "Effects of Heat and Age," and the addition of information on overwriting and degaussing. Section 5 addresses DoD endorsed erasure standards. Recently developed storage technologies and disk exercisers are discussed in Section 6. Section 7 addresses areas needing further investigation and provides references to additional information on the science of magnetics, as it pertains to magnetic remanence.

1.1 PURPOSE

The purpose of this publication is to provide information to personnel responsible for the secure handling of sensitive AIS memory and secondary storage media. (However, this guidance applies to any electronic or magnetic storage media, e.g., instrumentation tape.) This guideline provides information relating to the clearing, purging, declassification, destruction, and release of most AIS storage media. While data remanence is not a directly evaluated criterion of trusted computing systems, it is an issue critical to the safeguarding of information used by trusted computing systems and, as such, is addressed in thA5 National Computer Security Center (NCSC) guideline. The NCSC publishes this document because the community using trusted computing systems has expressed the desire for this information. Additionally, readers should note that this is a guideline only and they should not use it in lieu of policy.

1.2 HISTORY

As early as 1960 the problem caused by the retentive properties of ASI storage media (i.e., data remanence) was recognized. It was known that without the application of data removal procedures, inadvertent disclosure of sensitive information was possible should the storage media be released into an uncontrolled environment. Degaussing, overwriting, data encryption, and media destruction are some of the methods that have been employed to safeguard against disclosure of sensitive information. Over a period of time, certain practices have been accepted for the clearing and purging of AIS storage media.

A series of research studies were contracted by the DoD to the Illinois Institute of Technology, Research Institute and completed in 1981 and 1982. They have confirmed the validity of the degaussing practices as applied to magnetic tape media. [19] Additional research conducted at the Carnegie-Mellon University using communication theory and magnetic modeling experiments designed to detect digital information from erased disks has provided test data on the erasability of magnetic disks. [11, 21, and 22] This work, along with DoD research that has not yet been released, provides the basis for the disk degaussing standard. More studies are planned or underway to ensure the adequacy of DoD degaussing standards.

On 2 January 1981, the Director of the National Security Agency assumed responsibility for computer security within the Department of Defense. As a result, the Department of Defense Computer Security Center (DoDCSC), officially chartered by DoD Directive 5215.1, was established at the National Security Agency. (3] The DoDCSC Division of Standards (now Division of Standards, Criteria, and Guidelines)

was subsequently formed and tasked to support a broad range of computer security

related subjects. The DoDCSC became the NCSC in 1985, as amended in National Security Decision Directive 145. [15] As part of its mission to provide information useful for the secure operation of AISs, the NCSC published the Department of Defense Magnetic Remanence Security Guideline, which is version 1 of this guideline.

2 GENERAL INFORMATION

An AIS and its storage media should be safeguarded in the manner prescribed for the highest classification of information ever processed by the AIS. That is, until the AIS and its associated storage media are subjected to an approved purging procedure and administratively declassified. There should be continuous assurance that sensitive information is protected and not allowed to be placed in a circumstance wherein a possible compromise can occur. There are two primary levels of threat that the protector of information must guard against: keyboard attack (information scavenging through system software capabilities) and laboratory attack (information scavenging through laboratory means). Procedures should be implemented to address these threats before the AIS is procured, and the procedures should be continued throughout the life cycle of the AIS.

2.1 USE OF THIS GUIDELINE

Designated Approving Authorities and Information System Security Officers (ISSOs) may refer to this guideline when selecting or evaluating specific methods to clear, purge, declassify, or destroy AIS storage media. DoD components may include the information provided in this guideline in their security training and awareness program; however, they should not use this guideline in lieu of existing policies.

Guidelines in this document have two degrees of emphasis. Those that are most important to the secure handling of AIS storage media have such wording as "the ISSO should . . . ." Guidance of lesser criticality has such wording as "it is good practice" or "it may be." Thus, the word "may" denotes less emphasis or concern than the word "should."

2.2 IMPORTANT DEFINITIONS

This section provides definitions and their amplification critical to understanding the issues in remanence. A comprehensive glossary follows Section 7.

Clearing: The removal of sensitive data from an AIS at the end of a period of processing, including from AIS storage devices and other peripheral devices with storage capacity, in such a way that there is assurance, proportional to the sensitivity of the data, that the data may not be reconstructed using normal system capabilities, i.e., through the keyboard. (This may include use of advanced diagnostic utilities.) An AS need not be disconnected from any external network before a clear. [1, draft version]

Clearing can be used when the secured physical environment (where the media was used) is maintained. In other words, the media is reused within the same AIS and environment previously used.

In an operational computer, clearing can usually be accomplished by an overwrite of unassigned system storage space, provided the system can be trusted to provide separation of the storage space and unauthorized users. For example, a single overwrite of a file or all system storage, if the circumstance warrants such an action, is adequate to ensure that previous information cannot be reconstructed through a keyboard attack. Note: Simply removing pointers to a file, which can occur when a file is simply deleted in some systems, will not generally render the previous information unrecoverable through normal system capabilities (i.e., diagnostic routines).

Purging: The removal of sensitive data from an AIS at the end of a period of processing, including from AIS storage devices and other peripheral devices with storage capacity, in such a way that there is assurance, proportional to the sensitivity of the data, that the data may not be reconstructed through open-ended laboratory techniques. An AIS must be disconnected from any external network before a purge. [17]

Purging must be used when the secured physical environment (where the media was used) will not be maintained. In other words, media scheduled to be released from a secure facility to a non-cleared maintenance facility or similar non-secure environment must be purged.

Note: The purging definition allows a hierarchy of data eradication procedures, although current standards do not take advantage of this. That is, removing data with "assurance, proportional to the sensitivity of the data, that the data may not be reconstructed" implies that standards can be developed to be applied hierarchically. For example, a standard could be developed that allowed a security officer to degauss CONFIDENTIAL tapes by 80 db, SECRET tapes by 90 db, etc. Practice has shown, however, that this is not a feasible approach. Authorized clearing and purging procedures are detailed in DoD 5200.28-M and sometimes further amplified in DoD component regulations.

Declassification: A procedure and an administrative action to remove the security classification of the subject media. The procedural aspect of declassification is the actual purging of the media and removal of any labels denoting classification, possibly replacing them with labels denoting that the storage media is unclassified. The administrative aspect is realized through the submission to the appropriate authority of a decision memorandum to declassify the storage media.

Whether declassifying or downgrading the storage media, the memorandum should include the following:

a. A description of the media (type, manufacturer, model, and serial number).
b. The media's classification and requested reclassification as a result of this action.
c. A description of the purging procedures to include the make, model number, and serial number of the degausser used and the date of the last degausser test if degaussing is done; or the accreditation statement of the software if overwriting is done; or the description of and authorization to use the purging procedure if the purging procedure is different from the preceding procedures.
d. The names of the people executing the procedures and verifying the results.
e. The reason for the downgrade, declassification, or release.
f. The concurrence of the data owner that the action is necessary.
g. The intended recipient or destination of the AIS and storage media.
Coercivity: Measured in oersteds (Oe), is a property of magnetic material used as a measure of the amount of applied magnetic field (of opposite polarity) required to reduce magnetic induction to zero from its remanent state, i.e., taking the media

from a recorded state to an unrecorded state. Coercivity values are available from the manufacturer or vendor.

Type I Tape: Magnetic tape with coercivity not exceeding 350 Oe (also known as low-energy tape), for example, iron oxide coated tape. Note: The maximum coercivity level has changed from 325 Oe to 350 Oe.

Magnetic disks, i.e., oxide particles on a metal substrate, also have varying coercivity levels. Research has shown, however, that the physical remanence properties of disks are easier to address. Because of this, disks are treated as Type I media and are discussed in more detail later.

Type II Tape: Magnetic tape with coercivity ranging from 351 to 750 Oe (also known as high-energy tape), for example, chromium dioxide coated tape.

The determination of the Types l and II definitions was largely a result of the tape manufacturing industry. Low-energy tapes were developed first, and they have coercivities around 300 Oe + 10%. The next generation tape was high-energy tape, whose coercivity is around 650 Oe + 10%. There have been no naturally occurring plateaus for which to define a Type Ill tape. As a practical matter, there are no degaussers that can yet meet the requirements of National Security Agency/Central Security Service (NSA/CSS) Specification L14-4-A for tapes above Type II. [13]

Type III Tape: Magnetic tape with coercivity above 750 Oe, for example, cobalt-modified iron oxide coated tape and metallic particle coated tape. This definition is provided so these media may be discussed.

Degausser: A device that can generate a magnetic field for degaussing magnetic storage media. A Type l degausser can purge Type I tapes and all magnetic disks. A Type II degausser can purge both Types I and II tapes. There are, at present, no Type III degaussers. Currently, all Type I, II, and III tapes may be cleared with a Type I degausser. However, Type III tapes with higher than the current maximum coercivity may be developed that would not be clearable with a Type I degausser. Refer to the DPL for Type III degausser availability. Section 3 discusses degaussers further.

Permanent Magnet Degausser: A hand-held permanent magnet that has satisfied the requirement to degauss floppy disks, disk platters, magnetic drum surfaces, bubble memory chips, and thin film memory modules. It is not used to degauss magnetic tape.

2.3 OBJECT REUSE AND DATA REMANENCE

The issue of data scavenging on multiuser systems was recognized to be an area of concern long before the DoD 5200.28-STD, Trusted Computer System Evaluation Criteria (TCSEC), [20] became the metric with which to evaluate trusted systems. The TCSEC reflects this concern with its requirement that a Trusted Computing Base (TCB) have a mechanism that enforces an object reuse policy. This mechanism must ensure that no user can use the TCB interface to recover another user's data from recycled storage media (e.g., memory or disk pages). Object reuse in trusted computing systems is comparable (in most respects) to "clearing."

Object reuse can be implemented so that the address space that contained the object (file) is cleared upon deallocation (the net result is that unallocated address space is cleared) or upon allocation (the net result is that unallocated address space may contain data residue). (Note: There are other ways to implement object reuse which do not involve clearing.) Information from a common data storage pool cannot normally be retrieved through the keyboard.

Some comparisons have been made between trusted systems that satisfy the object reuse requirement and overwrite programs that do only clearing or purging; however, it should be noted that overwrite programs cannot be trusted in the same sense as trusted systems. This is primarily because of the environment in which overwrite programs must operate.

Trusted systems are designed with an object reuse mechanism that is protected and supported by the TCB, substantiating the degree of trust placed in the object reuse mechanism. Commercially available overwrite programs are usually designed to operate on several different systems and are not evaluated with the same rigor as trusted systems; however, any overwrite program should be protected from unauthorized modification. These two security features provide a similar aspect of data confidentiality but satisfy different computer security requirements.

3 DEGAUSSERS

DoD 5200.28-M requires that degaussing equipment be tested and approved by a laboratory of a DoD component or a commercial testing laboratory where the evaluation tests may be certified. Test methods and performance criteria are promulgated in DoD 5200.28-M. National Security Agency/Central Security Service (NSA/CSS) Specification L14-4-A, Magnetic Tape Degausser, [13] is an updated version of DoD 5200.28-M degausser testing requirements. The NSA/CSS has ensured that degausser testing criteria are current by publishing NSA/CSS Specification L14-4-A.

3.1 A PRIMER

Data are stored in magnetic media by making very small areas called magnetic domains change their magnetic alignment to be in the direction of an applied magnetic field. This phenomena occurs in much the same way that a compass needle points in the direction of the earth's magnetic field. Degaussing, commonly called erasure, leaves the domains in random patterns with no preference to orientation, thereby rendering previous data unrecoverable. There are some domains whose magnetic alignment is not randomized after degaussing. The information that these domains represent is commonly called magnetic remanence. Proper degaussing will ensure that there is insufficient magnetic remanence to reconstruct the data.

Erasure via degaussing may be accomplished in two ways: in AC erasure, the media is degaussed by applying an alternating field that is reduced in amplitude over time from an initial high value (i.e., AC powered); in DC erasure, the media is saturated by applying a unidirectional field (i.e., DC powered or by employing a permanent magnet).

3.2 DEGAUSSER TESTING

The DoD has adopted the National Security Agency security standard for degaussing equipment, which requires degaussers to reduce a special worst-case analog test signal by 90 decibels (db). More simply stated, degaussing must reduce the test signal to one billionth (1 part in 109) of its original strength. However, the signals recorded on magnetic media are easier to erase than the worst-case test signal. This signal is a test signal that magnetically saturates a tape and is set forth in references 1 and 13. After the test signal is recorded on the tape, the tape is degaussed and the residual signal is evaluated against the 90 db standard. This quantifies degausser effectiveness.

3.3 LABELING TAPES

It is difficult to distinguish the different types of magnetic tape from appearance alone. For this reason, it is recommended that responsible personnel ensure that type labels (i.e., Type I, II, or III) are applied to the tape reels upon initial use. The label should remain on the reel until the tape is cut from the reel or the reel is destroyed.

In some cases, adding another label to the tape could introduce the possibility of operator error in shops where the reel is already crowded with labels. Some facilities require the security officer to use the manufacturer's label to determine tape coercivity. In any case, strict inventory controls should be in place to ensure that tapes can be identified by type so the correct purge procedure is used.

3.4 DEGAUSSER PRODUCTS LIST (DPL)

The list of magnetic degaussers that satisfy the requirements in NSA/CSS Specification L14-4-A is included in the NSA's Information Systems Security Products and Services Catalogue [10] as the DPL. The catalogue is up