Defense Logistics Agency. Turn-in Guidance for Disposition of Unclassified Computer Hard Drives

Similar documents
Report No. D September 21, Sanitization and Disposal of Excess Information Technology Equipment

NATIONAL SECURITY AGENCY CENTRAL SECURITY SERVICE NSA/CSS POLICY MANUAL Issue Date: 15 December 2014 Revised:

State of Vermont. Digital Media and Hardware Disposal Standard. Date: Approved by: Policy Number:

CD ROM, Inc Commercial Catalog. Destruction and Recycling Services

Washington Headquarters Services ADMINISTRATIVE INSTRUCTION

CMC REQUIRED PROCEDURES

BACKUP SECURITY GUIDELINE

PDC 459 Establish Utilization Code H/New MILSTRIP-Authorized Value for First Position of Requisition Document Number Serial Number for MSC

CCTM IA CLAIMS DOCUMENT (ICD) Data Eliminate Ltd

Electronic Crime Scene Investigation: A Guide for First Responders, Second Edition

MEDIA SANITIZATION MANUAL

Dell Service Description

Information Technology Services Guidelines

Digital Data Destruction D3 Services, Inc.

Consolidated Storage Program (CSP) Defense Property Accountability System (DPAS) Warehouse Module Reference Guide

Chapter 1. The largest computers, used mainly for research, are called a. microcomputers. b. maxicomputers. c. supercomputers. d. mainframe computers.

Form #57, Revision #4 Date 7/15/2015 Data Destruction and Sanitation Program. Mobile (ON-SITE) Data Destruction/Shredding Services

Media Disposition and Sanitation Procedure

Fixed Asset Policy & Procedures. Content

Service Description: Dell ProManaged Asset Recovery Services IT Asset Recycling

NGA Instruction for Determining Property Accountability. a. Primary. NGA PD 4000R2, Policy Directive for Logistics, 24 November 2003.

SUPPLIER QUALITY MANAGEMENT SYSTEM QUESTIONNAIRE

The Defense Logistics Agency has provided supplies to America s fighting forces for 50 years. DLA was, and is, a vital player in America s national

**************** UNCLASSIFIED / **************** Precedence: ROUTINE DTG: Z Aug 12 Originator: DON CIO WASHINGTON DC(UC) UNCLASSIFIED//

Product Data Reporting and Evaluation Program (PDREP) PDREP Search Tool

Student Guide.

Axis Technologies Computer Hardware and Electronics Portfolio Categories

Instructions for Automated Toner Replenishment for Qualified Networked Printer Devices on Toshiba Unified Print Program

SAMPLE ELECTRONIC DISCOVERY INTERROGATORIES AND REQUESTS FOR PRODUCTION

Harbinger Escrow Services Backup and Archiving Policy. Document version: 2.8. Harbinger Group Pty Limited Delivered on: 18 March 2008

COVER SHEET OF POLICY DOCUMENT Code Number Policy Document Name

SECTION 2 - GENERAL PROCESSING

HIPAA Security. assistance with implementation of the. security standards. This series aims to

LYFORD CISD FIXED ASSET POLICIES & PROCEDURES

FIXED ASSET GUIDELINES

STANDARD OPERATING PROCEDURE

LAUSD. Instructions for Service & Supplies Requests. EU Portal Instructions Version 7.0 Page 1 of 11

Other terms are defined in the Providence Privacy and Security Glossary

The second section of the HIPAA Security Rule is related to physical safeguards. Physical safeguards are physical measures, policies and procedures

Practical Application How to Use a Flash Drive

Capabilities Statement

COLORADO COMMUNITY COLLEGE SYSTEM SYSTEM PRESIDENT S PROCEDURE ELECTRONIC COMMUNICATIONS MANAGEMENT AND RETENTION PROCEDURES

That s why outsourcing using a Qualified Contractor is the best solution to the problem of assuring a compliant hard drive destruction audit trail.

Blocal government bulletin b

O.R.C ;

Excerpt of Cyber Security Policy/Standard S Information Security Standards

Document Management Plan Preparation Guidelines

SPECIAL KIDS PROGRAM. Program Description and Guidelines

UMBC POLICY ON ELECTRONIC MEDIA DISPOSAL UMBC# X

DEFENSE LOGISTICS AGENCY HEADQUARTERS 8725 JOHN J. KINGMAN ROAD FORT BELVOIR, VIRGINIA

SUMMARY: The Office of the Secretary of Defense proposes to. alter a system of records notice DPFPA 02, entitled Pentagon

Blanket Purchase Agreement Attachment C Ordering Guide. DLT Solutions/Autodesk. Blanket Purchase Agreement (BPA): N A-ZF30

COMPUTER & ELECTRONICS DISPOSITION CONTRACT MNSCU CONTRACT #: CST - 125

Self-Audit Checklist

Protecting Data in Decommissioned IT Assets: Factors, Tools and Methods

Defense Logistics Agency INSTRUCTION. SUBJECT: Department of Defense (DoD) Financial Management (FM) Certification Program

Department of Defense INSTRUCTION. Accountability and Management of DoD Equipment and Other Accountable Property

CITY UNIVERSITY OF HONG KONG. Inventory and Ownership Standard

There are many examples of sensitive information falling into the wrong hands. What s the worst that can happen? The worst has already happened.

Walton Centre. Asset Management. Information Security Management System: SS 03: Asset Management Page 1. Version: 1.

NOAA National Disposal Plan for Personal Property Management January 2016 Update 9.5

Winzer Corporation 1 Revision: 4.0

Prof. Dr. M. H. Assal

1. ORIGINATOR: Defense Logistics Agency (DLA) J-331, (DSN 427)

Department of Energy Personal Property Management Program

NEC USB PortBar with the Driver Installation Diskette

2. Empty the Recycle Bin. Some users need to be reminded to periodically empty the Recycle Bin.

NEC USB PortBar with the Driver Installation Diskette

POLICY STATEMENT Commonwealth of Pennsylvania Department of Corrections

Ohio Supercomputer Center

E. Custodian - the Vice President for Administrative Services and Finance or designee.

s t a t e - o f - t h e - a r t i n h i g h s p e e d t r a c k i n g a n d t r a c i n g Smart Track Never Lose Track of an Item Again

Commanding Officer and Executive Officer. Information and Personnel Security Reference Handbook

Department of Defense INSTRUCTION. Presidential Recognition on Retirement from Military Service

STATE-OF-THE-ART IN HIGH SPEED TRACKING AND TRACING. Smart Track. Never Lose Track of an Item Again!

Overview. Responsibility

IT Solutions Resource Management Consulting Group th Street NW Suite 206 * Washington DC * Office (202)

Equipment Management Guidelines

CENTER FOR NUCLEAR WASTE REGULATORY ANALYSES

the the gear that keeps the supply chain running

Department of Energy Personal Property Management Program

Contents. Instructions for Using Online HIPAA Security Plan Generation Tool

Approved By: Agency Name Management

FEDERAL PROPERTY MANAGEMENT PROCEDURE GUIDE

CITY UNIVERSITY OF HONG KONG. Information Classification and

Data Recovery - What is possible to recover and how? Data Erasure - How to erase information in a secure way. Åke Ljungqvist, Country Manager Sweden

Property Management Manual

Defense Logistics Agency Disposition Services Afghanistan Disposal Process Needed Improvement

**************** UNCLASSIFIED / **************** Precedence: ROUTINE DTG: Z Aug 12 Originator: DON CIO WASHINGTON DC(UC)

5 FAM 440 ELECTRONIC RECORDS, FACSIMILE RECORDS, AND ELECTRONIC MAIL RECORDS

Mobile Devices and Systems Lesson 02 Handheld Pocket Computers and Mobile System Operating Systems

FMA-RE-001. Disposition of Surplus Material. Approved by: Chairman, Fort Monroe Authority Board of Trustees. Fort Monroe Authority Executive Director

Department of Defense MANUAL. DoD Integrated Materiel Management (IMM) for Consumable Items: Reporting, Auditing, and Financial Management

Electronic Asset Disposition

Introduction. Conducting a Security Review

4 FAH-2 H-210 CHECK STOCK, SIGNATURE DIE, INTERNAL CONTROLS AND FILE MANAGEMENTS

1. Introduction 2. New Responsibilities 3. Transactional Processes 4. Use of PeopleSoft User Role

Department of Defense INSTRUCTION

HIPAA Privacy & Security Health Insurance Portability and Accountability Act

DENVER PUBLIC SCHOOLS WAREHOUSE SERVICES HANDBOOK

Transcription:

Defense Logistics Agency Turn-in Guidance for Disposition of Unclassified Computer Hard Drives 1

Foreword It is very important to check all your computer equipment and property prior to turn-in to the DRMO for any Secret, Classified, Confidential, Tempest or Hazardous indicator! 2

Quick Guide CPU Turn-In Requirements without Hard Drives DL Form 1348-1A or 1348-2 (filled-out completely) CPU chassis serial number in block 26 (optional). 1 required statement either on/or with the DD Form 1348-1A or 1348-2 and 2 optional statements (refer to chart #9 for details). Label on chassis using DL Form 2500 or equivalent. CPUs Turn-In Requirements with Hard Drives DD Form 1348-1A or 1348-2 (filled-out completely) CPU chassis serial number or hard drive serial number in block 26 (optional). 1 required statement either on or with the DD Form 1348-1A or 1348-2 in block 27 (refer to chart #16 for details). Label on chassis using DL Form 2500 or equivalent 3

Electronic Turn-In Document (ETID) Interested in participating? Click CONUS/OCONUS Disposal Sites- 4

Disposal Turn-in Document (DTID) View, fill-out and print a DTID (DD Form 1348-1A or 1348-2) 5

Disposal Turn-in Document (DTID) DD Form 1348-1A or 1348-2 - required information: Columns: 25-29 QUANTITY - Actual Quantity 74-80 UNIT PRICE - Unit Price Block: 1. TOTAL PRICE - Total Price 2. SHIP FROM - Your unit name address 17. NOMENCLATURE - i.e., CPU, printer, monitor 24. DOCUMENT NUMBER & SUFFIX - Your DoDAAC, Julian Date & Document Serial Number 25. NATIONAL STOCK NO. & ADD - NSN or FSC: 7021-00 CPU, 7025-00 Monitor, 7025-00 Printer 26. RIC Your DoDAAC, Julian Date & Serial Number 27. ADDITIONAL DATA POC information. You may add optional statements/certifications 6

Disposal Turn-in Document (DTID) A DD Form 1348-1A or 1348-2 (DTID) must accompany all property. A separate DTID is required for each National Stock Number (NSN) or Federal Supply Group (FSG)/Federal Stock Class (FSC) w/nomenclature. The DTID must be properly filled-out. POC information should be included, (i.e. print name, signature, phone number and address. 7

How To Turn-In CPUs Without Hard Drives 8

CPUs Without Hard Drives The following statement must be on (in block 27 Additional Data) or with * the 1348-1A: The residue identified by this document meets the disposition requirements in accordance with the DoD Memorandum, Disposition of Unclassified Computer Hard Drives, dated June 4. 2001. The DTID should also include: Print name, rank/grade and signature of individual certifying the above information Optional statements in block 27: Hard Drives(s) has been removed. Statement or letter stating CPU contains no classified, confidential or hazardous material. * Currently ETID does not allow insertion of this statement on the DTID 9

CPUs Without Hard Drives Ensure the hard drive is in fact removed Label CPU chassis/housing, use suggested DL Form 2500 Remove memory sticks from other forms of computer equipment, i.e., handheld computers (e.g. palm pilots, organizers, etc.) Internal devices i.e., graphic, sound, network or controller cards, may stay in the CPU. 10

CPUs Without Hard Drives Ensure the following computer medias & cards are also removed from all turn-in computer equipment: Compact Flash Cards Secure Data Cards Micro-drives Smart Card Media CD-ROM Media Multi-media Cards Memory Sticks Back-up Tapes Floppy Diskettes PCMCI Cards Zip Media 11

CPUs Without Hard Drives A DL Form 2500 is the suggested label to use on all CPUs. CERTIFICATION OF HARD DRIVE DISPOSITION Check if hard drive or similar data storage components have been removed. This certifies this hard drive: Serial No. Barcode No. Make/Model. was Overwritten I Degaussed I Destroyed in accordance with DoD Memo dated June 4, 2001, "Disposition of Unclassified DOD Computer Hard Drives on (Date) Software /Degausser (Manufacturer, Product Version, Date) Method of Destruction (e.g., approved metal destruction facility) DTID No. / Hand Receipt No. Generator Name Phone Email NOTE: When hard drive is removed, use chassis serial number. Printed Name Rank/Grade Signature Date DLA FORM 2500, APR 2013 (Replaces all similar forms) 12

How To Turn-In CPUs With Hard Drives 13

CPUs With Hard Drives Ensure the hard drive has been degaussed or overwritten IAW the DoD Memo Disposition of Unclassified Computer Hard Drives, dated June 4, 2001. Label CPU chassis/housing, use DL Form 2500 or equivalent. Ensure hard drives from other forms of computer equipment, i.e., notebooks, desktops, laptops, and docking stations are degaussed or over-written. Internal Devices i.e., graphic, sound, networks or controller cards, may stay in the CPU. 14

CPUs With Hard Drives Ensure the following computer medias & cards are also removed from all turn-in computer equipment: Compact Flash Cards Secure Data Cards Smart Card Media Multi-media Cards CD-ROM Media Memory Sticks Back-up Tapes Micro-drives Floppy Diskettes PCMCI Cards Zip Media 15

CPUs With Hard Drives The following statement must be on (in block 27 Additional Data) or with * the 1348-1A : The residue identified by this document meets the disposition requirements in accordance with the DoD Memorandum, Disposition of Unclassified Computer Hard Drives, dated June 4, 2001. The DTID should also include: Print name, rank/grade and signature of individual certifying the above information * Currently ETID does not allow insertion of this statement on the ETID. 16

CPUs With Hard Drives A DL Form 2500 label NOTE: When using this form attached to the hard drive itself, indicate the serial number for the actual hard drive. If the hard drive is still left in the CPU, it is not necessary to list the serial number. This avoids unnecessary work and does not lead to destruction of otherwise useful computers that can be donated to schools or other qualified worthy causes. Printable Hard Drive Certification Form: DL Form 2500.pdf. The DL Form 2500.pdf form is sized so it can printed on sticky labels, Avery Label 5164 or 'PRES-a-ply' Label 30604. There are 6 labels, at 3.5" x 4" per sheet. DLA developed an optional label, based on ASD Memo, Attachment 4, dated 04 June 2001, that also contains a block to check if turning in chassis w/hard drive(s) removed. It can be printed on sticky labels, i.e., Avery 5164 or Pres-a-ply 30604. 17

CPUs With Hard Drives - CPUs with hard drives installed must have all data permanently removed prior to being removed from DOD custody. OSD Memo for Disposition of Unclassified DoD Computer Hard Drives NSA Manual for Storage Device Declassification (Sanitizing, declassification and release) Degaussers - National Security Agency (NSA) Evaluated Products List DOD 5220.22-M (National Industrial Security Program Operating Manual) - There are many commercial software programs and hardware that meet DOD requirements. Ensure that the method used to sanitize your hard drives is in compliance with DOD 5220.22 and the above publications. 18

Hard Drive Turn-In 19

Hard Drive Turn-In A filled-out DL Form 2500 or equivalent is required on all hard drives. (old DLIS 1867 shown in picture to right) The hard drive serial number! If the hard drive is still left in the CPU, it is not necessary to list the serial number. 20

Hard Drive Turn-In A DLForm 2500 label PDF form: DL Form 2500 - Certification of Hard Drive Disposition. The DL Form 2500.pdf form is sized so it can printed on sticky labels, Avery Label 5164 or 'PRES-a-ply' Label 30604. There are 6 labels, at 3.5" x 4" per sheet. DLA developed an optional label, based on ASD Memo, Attachment 4, dated 04 June 2001, that also contains a block to check if turning in chassis w/hard drive(s) removed. It can be printed on sticky labels, i.e., Avery 5164 or Pres-a-ply 30604. 21

New and Unused Hard Drives New Hard Drives (in un-broken packaging). No labeling or certification requirements exist. Unused Hard Drives (not in original packaging). The ETID/DTID must contain a signed certification such as Hard Drive(s) has/have not been used. 22

All Other Computer Related Devices 23

Hard Drive Turn-In A label is not required if hard drive is destroyed and turned in as scrap. The following statement must be on/or with the DTID if the generator requires verification that the hard drives were turned in to the DRMO as scrap: The residue, identified by this document, is derived from the processing of computer hard drives based on the requirements of the Assistant Secretary of Defense letter dated June 4, 2001, subject, Disposition of Unclassified DoD Computer Hard Drives. Complete standard fields: Box 2 - SHIPPED FROM BLOCK Field 24 - DOCUMENT NUMBER Field 26 - POC Information Not required: Qty, Price, NSN Annotation 24

Other Computer Related Devices Monitors Printers (toner cartridges must be removed) Keyboards Speakers Modems Mouse/Mice Plotters (toner cartridges must be removed) External Devices All others that do not fall under the category of classified, secret, tempest or hazardous waste. 25

Other Computer Related Devices Filled-out DD Form 1348-1A or 1348-2 No label is required No serial numbers required (unless required by your SA/Supply) Each NSN, FSG/FSC, type property require it s own DTID (DD Form 1348-1A or 1348-2) 26

Find the Federal Supply Class of your property by using H-2 Federal Supply Classifications Find information on your property by using 27

TEMPEST Technology Items/Equipment (TTIE) 28

TTIE DRMS-I 4160.14, Section III, Special Processing DoD 4160.21-M-V3, Enclosure 3 Appendix, Category 11 Definition - TEMPEST is a term used to denote measures for preventing compromising emanations (electronic/ electromagnetic) from electrically operated devices. More simply put, TTIE has been manufactured with additional devices built in to prevent monitoring. Identifying TTIE: If the TEMPEST application is to an item which is specifically designed for military use, complete destruction to preclude restoration as an item for its original function (this includes both entire end items and individual components, as applicable). If the TEMPEST application is to a commercially available item, e.g., IBM-XMT or AT personal computer, the generating activity will sanitize the equipment of all classified/sensitive data and software prior to turn-in to the Disposition Service Site. The turn-in document will be annotated that item has TEMPEST application and has been sanitized prior to turn-in. These items will then be considered Strategic List Items and incorporate all appropriate controls. 29

TTIE The following indicators may assist in the identification of TEMPEST Technology Items/Equipment (TTIE): Documentation sometimes is marked with the word TEMPEST. Attached SF Form 120, Reports of Excess Personal Property, cleared by DISA may reflect IT is TEMPEST. Review of data plate on rear of property reveals the word TEMPEST. Equipment is embossed with TEMPEST warnings. Manufacturer model number puts the letter T within the number, e.g., CPT Corp., Model 8000T. Tags may be glued to equipment stating, This machine processes up to top secret, or lower classification such as confidential. 30

Web Links 31

Web Links -Disposition Services Home Page -Publications: This web page contains Disposition Services and other pertinent publications. Usually in a pdf format. -Federal Supply Classification Handbook (H2) look up FSC/LSN (4 first numbers of an NSN) -OSD Memo for Disposition Of Unclassified DOD Computer Hard Drives -WebFlis locates NSN using Part Number. Also provides property information - NSA Central Security Service Home Page: use search function to find pertinent information security regulations and approved vendor lists - Defense Information Systems Agency (DISA) Approved IA product listings & Certifications - U.S Department of Defense Home Page 32