A finance firm ships its decommissioned drives to an outside disposal vendor for shredding. Auditors require documented proof, for chain of custody, that each specific drive was actually destroyed. What should the technician make sure the vendor provides?
- AA signed non-disclosure agreement committing the vendor to keep any recovered data confidential.
- BA recycling receipt confirming the vendor collected the sealed boxes of drives from the site.
- CA certificate of destruction that records each drive's serial number and the date it was destroyed. Correct
- DA full disk image of every drive taken before shipping so the data can be verified afterwards.
Why A is wrong: An NDA is a reasonable contractual control, but it protects confidentiality, not proof of destruction, so it does not satisfy the auditors' chain-of-custody evidence.
Why B is wrong: A collection receipt proves only that the drives were handed over, not that they were destroyed, leaving a gap in the destruction evidence trail.
Why C is correct: A certificate of destruction is the standard document that proves specific media were destroyed, giving auditors the chain-of-custody evidence they require.
Why D is wrong: Imaging the drives first creates an extra copy of the sensitive data and proves nothing about destruction, which runs counter to the goal.