Skip to content
arrow_back
search
ISM-0359 policy ASD Information Security Manual (ISM)

Proper Sanitisation of Non-Volatile Flash Memory

Non-volatile flash memory is wiped by overwriting it twice with random data, then checked to ensure it's clean.

record_voice_over

Plain language

This control is about making sure that the data stored on non-volatile flash memory is completely erased before disposing of the device or repurposing it. This is important because if old data isn't properly wiped, sensitive information could fall into the wrong hands, leading to privacy breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Non-volatile flash memory media is sanitised by overwriting it at least twice in its entirety with a random pattern followed by a read back for verification.
policy ASD Information Security Manual (ISM) ISM-0359
priority_high

Why it matters

If flash memory isn’t overwritten twice with random patterns and verified, sensitive data may remain recoverable when devices are reused or disposed of.

settings

Operational notes

Overwrite the entire flash medium at least twice with random patterns, then perform a full read-back verification to confirm the overwrite completed successfully.

Mapping detail

Mapping

Direction

Controls