Follow Manufacturer's Directions for Degaussing
Ensure magnetic media is degaussed according to the manufacturer's instructions to properly erase data.
Plain language
This control is all about ensuring that when you erase data from magnetic storage, like tapes, you do it correctly by following the machine maker's guidelines. If you skip this, old data might not be fully erased and could fall into the wrong hands, leading to privacy breaches or data theft, especially in sensitive industries.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Feb 2022
Control Stack last updated
19 Mar 2026
E8 maturity levels
N/A
Official control statement
Product-specific directions provided by degausser manufacturers are followed.
Why it matters
Not following manufacturer degaussing directions (cycle, field strength, media compatibility) can leave data recoverable, causing breaches and penalties.
Operational notes
Verify correct degauss cycle and media type per the degausser manufacturer; keep firmware/manuals current and record settings used for each job.
Implementation tips
- The IT team should verify that all degaussers in use are the right type for the media being erased. Check the manufacturer's specifications for compatibility before proceeding to degauss any tapes or drives.
- The designated staff member, usually in IT or asset management, should follow the manufacturer’s step-by-step instructions when operating the degaussing equipment. This might include settings for strength and duration specific to each type of media.
- Managers should provide training to staff responsible for data destruction, ensuring they understand both the equipment and the importance of following the guidelines closely. Organising regular training refresher sessions can maintain standards.
- A procurement officer should keep a record of manufacturer manuals and updated instruction documents for each degaussing device. They should store these digitally in an easily accessible location for the team to reference.
- The IT department should schedule routine checks and maintenance of the degaussers to ensure they are operating according to manufacturer specifications. This includes checking performance and calibrations, as recommended in the manual.
Audit / evidence tips
-
Askthe current manufacturer’s manual for each degausser: Confirm that staff are using the correct and up-to-date instructions
Goodincludes the latest manual version and storage in an accessible location
-
Goodincludes attendee lists, presentation materials, and training dates
-
Goodis the person completing each step as per the guidelines without deviation
-
Askthe maintenance logs of the degausser equipment
Goodshows logs of regular tests, actions taken, dates, and responsible persons
-
Askabout their understanding of the guidelines and how frequently they refer to them
Goodincludes staff being aware of where to find the instructions and how they follow them
Cross-framework mappings
How ISM-0362 relates to controls across ISO/IEC 27001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
| layers Partially meets (1) expand_less | ||
| Annex A 7.10 | ISM-0362 specifies adherence to manufacturer directions for degaussing magnetic media as a sanitisation measure | |
| handshake Supports (3) expand_less | ||
| Annex A 5.37 | ISM-0362 enforces following manufacturer’s directions for degaussing magnetic media, whereas Annex A 5.37 calls for documented procedures... | |
| Annex A 7.14 | ISM-0362 ensures quality control in degaussing as a sanitisation method, which supports the broader data removal requirement of Annex A 7.14 | |
| Annex A 8.10 | Annex A 8.10 requires deletion of unneeded information | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.