A pharmaceutical research firm is decommissioning a server room that held mixed media: solid-state drives with clinical trial data, magnetic tapes from legacy backups, and several optical discs containing draft patents. The CIO wants a single destruction method applied to all media to simplify the project. As the asset security lead, what is the BEST response?
- AAgree, and use a cross-cut shredder rated for optical media, since shredding physically destroys all three media types
- BPush back and select a destruction method per media type aligned to the data classification and recognised sanitisation guidance Correct
- CAgree, and degauss everything in a single pass because degaussing is media-agnostic and irreversible
- DAgree, and incinerate all media together in a certified facility because incineration is recognised as the highest assurance method
Why A is wrong: Although shredding can be applied broadly, a single shredder rated for optical discs may not meet the particle-size requirements for SSDs holding regulated clinical trial data, and applying one method to all media without verifying suitability defeats the purpose of media-specific destruction standards.
Why B is correct: Sanitisation guidance such as NIST SP 800-88 maps destruction techniques to media type and data sensitivity. Choosing per-media methods aligned to classification is the defensible answer for regulated clinical and patent data, even if it adds project complexity.
Why C is wrong: Degaussing only works on magnetic media. It has no effect on solid-state drives or optical discs, so applying it as a universal method would leave high-sensitivity data recoverable on the non-magnetic media.
Why D is wrong: Incineration is highly effective, but committing to a single method without considering cost, environmental permits, transport custody, and whether each media type actually needs that level of assurance is poor risk management. The method must match the classification, not the convenience of a single process.