Skip to content
arrow_back
search
ISM-0836 policy ASD Information Security Manual (ISM)

Overwriting EEPROM for Complete Data Sanitisation

Erase EEPROM data by overwriting it with random data and checking it to ensure it's properly wiped.

record_voice_over

Plain language

This control is about making sure any data stored in EEPROM (a type of computer memory) is completely erased when it’s no longer needed. EEPROM holds onto information even when powered off, so if it's not properly wiped, sensitive data could fall into the wrong hands. By overwriting it with random patterns, we ensure that whatever was there before can't be recovered, protecting against data leaks and privacy breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety with a random pattern followed by a read back for verification.
policy ASD Information Security Manual (ISM) ISM-0836
priority_high

Why it matters

Failing to properly sanitise EEPROM increases the risk of sensitive data being retrieved after disposal, potentially leading to data breaches.

settings

Operational notes

Overwrite the entire EEPROM at least once with a random pattern, then read back the full device to verify the overwrite succeeded.

Mapping detail

Mapping

Direction

Controls