You can edit almost every page by Creating an account and confirming your email.

IT Asset Disposition

From EverybodyWiki Bios & Wiki


IT asset disposition (ITAD) is an entire specialized industry that is the culmination of decades of evolving best practices around how bulk electronic waste is disposed, which involves processes to secure data, comply with corporate data destruction policies, and to adhere to environmental laws. ITAD vendors manage that process of decommissioning hardware which includes including servers, workstations, laptops, mobile devices, and networking equipment.

ITAD is distinct from general electronic waste recycling. While recycling is one component of the disposition process, ITAD encompasses data destruction, chain of custody documentation, and serialized asset. The compliance documentation ultimately produced includes a per-device certificate of destruction to serve as evidence of regulatory compliance under relevant frameworks such as HIPAA, the Gramm–Leach–Bliley Act, Sarbanes-Oxley, and the General Data Protection Regulation.

History

Early development (1980s–1990s)

Before personal computers became standard corporate infrastructure, business computers were mostly composed of mainframes and minicomputers that were rarely replaced.[citation needed]

Organizations disposed of ewaste informally: auctions, donating to schools or nonprofits, with general office waste, or leaving it in storage. Data security implications were not understood.

Academic research (2003)

The first systematic academic documentation of the risks of hard drive disposal came from researchers Simson Garfinkel and Abhi Shelat, published in the January/February 2003 inaugural issue of IEEE Security and Privacy under the title "Remembrance of Data Passed: A Study of Disk Sanitization Practices."[1]

The researchers purchased 158 used hard drives from sources including eBay, used computer stores, and swap meets, and analyzed their contents. Of the 129 functional drives, 28 had no attempt at erasure whatsoever. On one formatted drive, more than 5,000 credit card numbers were recovered. Other drives contained medical records, personal financial records, and what appeared to be records from an ATM machine in Illinois. The study concluded that the secondary hard drive market was a risk, and that standard practices such as the Windows format command did not adequately remove sensitive data.[2] The paper became a foundational reference for both subsequent regulatory action and the formalization of the ITAD industry.

Regulations

The regulations that gave birth to ITAD came mainly from three pieces of U.S. federal legislation.

HIPAA

The Health Insurance Portability and Accountability Act (HIPAA), in 1996[3]

Gramm–Leach–Bliley Act and FTC Disposal Rule

The Gramm–Leach–Bliley Act (GLBA) of 1999

Sarbanes-Oxley Act

The Sarbanes-Oxley Act of 2002.

See also

References

  1. Garfinkel, Simson L.; Shelat, Abhi (2003). "Remembrance of Data Passed: A Study of Disk Sanitization Practices". IEEE Security and Privacy. 1 (1): 17–27. Bibcode:2003ISPri..99a..17G. doi:10.1109/MSECP.2003.1176992.
  2. "MIT: Discarded Hard Drives Yield Private Info". MIT News. January 15, 2003.
  3. "The Security Rule". HIPAA. U.S. Department of Health and Human Services. March 19, 2026.

External links

Category:Information technology Category:Electronic waste Category:Data security Category:Environmental law Category:Regulatory compliance


This article "IT Asset Disposition" is from Wikipedia. The list of its authors can be seen in its historical and/or the page Edithistory:IT Asset Disposition. Articles copied from Draft Namespace on Wikipedia could be seen on the Draft Namespace of Wikipedia and not main one.