Electronic Media Storage for Banks
Banks must ensure that removal of electronic protected information from electronic media before the media are made available for re-use.
Procedure:
Prior to making storage devices and removable media available for reuse, care must be taken to ensure that the device or media does not contain protected data.
If the device or media contains the only copy of protected data that is required or needed, a retrievable copy of the protected data must be made prior to reuse.
If the device or media contains the only copy of protected data that is required or needed, a retrievable copy of the protected data must be made prior to disposal.
If the device or media contains protected data that is not required or needed, and is not a unique copy, a data destruction tool must be used to destroy the data on the device or media prior to reuse. A typical reformat is not sufficient, as it does not overwrite the data.
If using removable media for the purpose of system backups and disaster recovery and the aforementioned removable media is stored and transported in a secured environment, the use of a data destruction tool between uses is not necessary.
« Information Risk Management for Banks | Home | State Bankers Association Directory »
Leave a Comment