Ninety-five million dollars in penalties, a moving company that shouldn't have been there, and the standard that quietly changed nine months ago.
At the end of life, a device stops being an asset and becomes a liability with a serial number. Disposal is the only gate in the lifecycle where getting it wrong doesn't cost you efficiency or budget — it costs you a regulator.
This episode covers what actually changed when NIST published SP 800-88 Revision 2 in September 2025 and withdrew Revision 1 the same day: the shift from a device-by-device technical manual to a program-level governance framework, the deferral of technique detail to IEEE 2883, the retirement of degaussing and multi-pass overwriting, and new language on establishing trust in a vendor's implementation. Then the regulatory stack — GLBA, FACTA, HIPAA, PCI DSS, Sarbanes-Oxley, Regulation S-P — and why one device can sit under five frameworks at once.
The centerpiece is a public enforcement case. Morgan Stanley paid $95 million across two regulators after handing roughly 4,900 devices to a moving and storage company with no data destruction experience. Devices reached an internet auction site with unencrypted customer information intact. Every control that failed was an asset management control.
Plus a listener question from Marcus in Fort Wayne on whether wiping drives in-house before they reach the ITAD vendor is duplicated effort.
IN THIS EPISODE
- NIST SP 800-88 Revision 2 — published September 2025, Revision 1 withdrawn the same day
- Why the media-specific tables were removed and what replaced them
- Clear, Purge, Destroy — what survived and what didn't
- Why degaussing and multi-pass overwriting are the wrong answer for modern media
- Cryptographic erase, and why it's the one technique NIST kept
- Should you wipe in-house before the ITAD vendor? A listener question
- The Morgan Stanley case: $95 million, 15 million customers, 42 unaccounted servers
- The regulatory stack, and why one device sits under five frameworks
- R2v3, e-Stewards, and NAID AAA — what each actually verifies
- The downstream gap auditors find over and over
- What makes a certificate of destruction defensible, and what makes it worthless
- Deaccession, the ledger, and why the shredder isn't the point
CHAPTERS
- (00:03) - Disposal’s Hidden Liability
- (01:31) - NIST 800-88 Changes
- (05:47) - The $95 Million Failure
- (10:21) - Rules, Vendors, and Proof
- (15:50) - The Ledger Matters Most
TRANSCRIPT
Click here to view the episode transcript.
SOURCES & FURTHER READINGNIST SP 800-88 Rev. 2 — current standard, published 26 September 2025
https://csrc.nist.gov/pubs/sp/800/88/r2/final
NIST announcement and summary of changes from Revision 1
https://www.nist.gov/news-events/news/2025/09/guidelines-media-sanitization-nist-publishes-sp-800-88r2
NIST SP 800-88 Revision 1 — withdrawal notice
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf
IEEE 2883 — Standard for Sanitizing Storage
https://standards.ieee.org/ieee/2883/10277/
SERI — R2v3 standard and certified facility directory
https://sustainableelectronics.org
e-Stewards certified recycler directory
https://e-stewards.org/find-a-recycler/
i-SIGMA — NAID AAA certification
https://isigma.org
Note: NIST SP 800-88 Revision 1 (2014) was withdrawn and superseded in September 2025. A great deal of the ITAD guidance still circulating online cites the withdrawn version.
LISTENER CASE FILES
Got a situation you'd like worked on air? Send it over — anonymized, sanitized, no company names. Real constraints, real politics, real budgets. operationalitam.com
ABOUT THE SHOW
Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.
Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.
Consulting enquiries and listener case files: operationalitam.com