The NSA must be vigilant in how they destroy their magnetic media. That's why there's a whole list of NSA certified degaussing equipment. Read on to learn more about this list and what it means for you.
WHAT is the Degausser EPL?
The NSA's Evaluated Products List (EPL) is a vital resource for those looking to purchase any piece of high security equipment. The NSA has lists for particular media types including paper shredders, optical media (CD/DVD) destroyers, punch tapes, disintegrators, and degaussers. You should never trust an NSA EPL list that you received anywhere other than www.nsa.gov. Other websites aren't guaranteed to have the most updated copy of the EPL, and some may fraudulently edit the data on the list to boost their own sales. The degausser EPL list specifically states which model numbers have been evaluated and found to satisfy the requirements for erasure of magnetic storage devices that retain sensitive and classified information. If a product is on the degausser EPL, this does not mean that the NSA endorses the particular product, it simply means that they have met all performance requirements.
What is NSA Approval?
The NSA has published standards for destroying hard drives that all US government agencies must comply with. According to the National Security Agency Central Security Service NSA/CSS Device Sterilization Manual, the only two ways that they recognize sanitization of of hard drive disks are via automatic degausser and degaussing wand.
For an item to become NSA evaluated, it must go through a lengthy and strenuous process, as it must meet very stringent requirements. Hard drives are defined by oersteds, which is the magnetic coercivity of the drive. The EPL lists degaussers by the coercivity of the magnetic storage devices that can be erased.
Magnetic storage devices are defined by their magnetic coercivity in units of Oe (Oersteds). Degaussers listed in the NSA Evaluated Products List are defined by the coercivity of the magnetic storage devices that can be erased. The NSA tests these products to determine which machines successfully erase sensitive and classified data.
DO I NEED AN NSA APPROVED DEGAUSSER?
While an NSA approved degausser is the ideal machine for federal and local governments, and industries that have strict requirements for erasing data, for other businesses the short answer is no.
Taking a deeper look into it, any company that deals with personal documents like financial statements or medical information, must be very careful as to how you destroy these files. There are many federal laws in place to protect customers and issue financial penalties to businesses who ineffectively destroy their customers records. These laws include the Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), Fair and Accurate Credit Transactions Act (FACTA), and the Sarbanes- Oxley Act (SOX). So, although it is not required for non-government companies to purchase an NSA approved degausser, it is recommended for assurance and piece of mind for you and your customers. It should be noted that while NSA evaluated products are tested by the government, there are many non-NSA approved degaussers that will work and destroy sensitive data just as well as their NSA approved counterparts.
If you're unsure which type of degausser will best suit your businesses needs, click on the button below to reach out to one of our expert representatives. We would be more than happy to hear from you.