Risk is the net negative impact of the exercise of vulnerability, considering both the probability and the impact of occurrence. Risk management is the process of identifying risk, assessing risk, and taking steps to reduce risk to an acceptable level. Ð National Institute of Science and Technology.
Disposal of surplus information technology (IT) equipment without taking appropriate measures to erase the information stored on the system's media can lead to the disclosure of sensitive information, embarrassment to the agency, costly investigations, and other consequences. Sharing of media within the government or between government and contractors also presents security issues. Federal agencies must establish policies and procedures to ensure the proper disposition of sensitive automated information. Sanitization of magnetic media means the removal of data from storage media so that, for all practical purposes, the data cannot be retrieved. The three techniques are commonly used for media sanitization, overwriting, degaussing, and destruction.