Start a free trial
Menu

AEDP-03

AEDP-03 sanitization guidance for advanced data storage memory

A NATO programme's acquisition manager or Security Officer specifying, procuring or approving sanitization procedures for ISR data storage media

AEDP-03 is NATO guidance on sanitizing flash, solid state and magnetic disk memory used in ISR data recorders, so a program's Security Officer can decide when the media is safe to reuse, declassify or dispose of.

Edition
C
Published
2016-08

What it is

AEDP-03 is the NATO Allied Engineering Documentation Publication that gives sanitization guidance for advanced data storage technology used in Intelligence, Surveillance and Reconnaissance (ISR) recorders: flash solid state memory, solid state disks, and magnetic disk or RAID storage built on the STANAG 4575 interface. It exists because Removable Memory Modules hold time-sensitive ISR data that has to be made unrecoverable before the media is reused, sent for repair outside a programme's control, or declassified. AEDP-03 does not bind by existing. It is guidance, and "national requirements may supersede this document"; the recommendation for nations to use it is recorded in STANREC 4750, a Standardization Recommendation rather than a ratified STANAG, so a nation's own officers decide whether and how it applies to their own systems. The edition in front of you is Edition C, promulgated 16 August 2016, superseding the previous version of the same edition.

Who AEDP-03 addresses

AEDP-03 speaks to NATO programme and security staff, not to a supplier's management system. Acquisition managers are told to "insure that the interfaces, control options, command structure, OS, and/or BIOS of procured data storage devices are capable of supporting the sanitization requirements of this AEDP in their systems". The acquisition Program Manager is expected to "verify by test and demonstration (i.e. First Article Inspection/Test)" that developed ADST memory implements the procedures the document defines. And the programme's own Security Officer determines the sanitization procedure for a system and, once memory has been purged or destroyed, "will assess the risk of declaring the memory element 'declassified' and determine if the required procedures have been properly followed". Those three roles, not a certification body and not this page, are who AEDP-03 puts in charge.

Three levels: Clear, Purge, Destroy

The document sets out three sanitization levels, applied differently by media type. Clear is "an 'Erase' of the entire directory and entire data storage element using a technologically appropriate and verified procedure", suited to routine reuse in a controlled environment; a plain file deletion does not qualify at any level, because it leaves the file's actual contents "vulnerable to recovery using trivial means". Purge "applies physical or logical techniques that render target data recovery infeasible using state of the art laboratory techniques". Destroy is the permanent physical destruction of the media, reserved for end of life or an emergency where destruction is the only option available.

Procedures by storage technology, and who chooses one

AEDP-03 works through separate Clear, Purge and Destroy procedures for FLASH solid state memory, for magnetic hard disk and RAID systems, and for solid state disk based Removable Memory Modules, because the same approach does not sanitize every technology the same way. It flags that a device's internal architecture is not always obvious from the outside, since "the new user may not be aware of the internal components of an RMM and must be able to rely on the specified or incorporated sanitization procedure", and it rules out degaussing for flash media outright: degaussing "must not be performed as a sanitization technique on flash-based storage devices". Which procedure applies to a given device, and with what parameters, is a decision AEDP-03 leaves with the programme's Security Officer under national policy, not something printed here as a step to follow: the document itself locates the risk of getting that judgement wrong with the user, customer, programme or security manager.

Cryptographic erase on self-encrypting drives

Where a device is a self-encrypting drive, cryptographic erase sanitizes the drive's encryption key rather than the data itself. AEDP-03 is explicit about when this may be relied on: it "should only be used when all data on an RMM has been automatically encrypted", and after the key is destroyed, verification that it is actually gone is still required before the memory counts as sanitized. For the underlying encryption and key-generation requirements, AEDP-03 points to NIST's published guidance rather than restating it.

Verification, failed cells and programme responsibility

A Purge is not complete until it is checked: "verifying the sanitization process is an essential step in maintaining confidentiality and is always a required step in the PURGE procedures", whether by reading the full media or by a defined sampling method. Failed or bad data blocks get their own judgement call: the document recommends overwriting them where practical, but leaves the residual risk to the Security Officer to weigh against the type of data and how it was recorded. Responsibility for all of this sits at programme level: "the determination of the risk that proper and appropriate sanitization has been effectively implemented resides with the Program Security Manager and should be based on the associated Country Policy". Programmes are also expected to plan for media that leaves their control, for example when it goes back to a manufacturer for repair, and to have a separate procedure ready for media that has failed catastrophically and can no longer be addressed through its normal interface.

How it's evaluated

There is no certification against AEDP-03, and the document names no accredited or notified body. Evaluation happens at programme level: the acquisition Program Manager verifies by test that developed ADST memory implements the required procedures, and the Security Officer, once memory has been purged or destroyed, assesses the risk of declaring the memory element "declassified" and confirms the procedures were followed. What the Security Officer checks for is documentation, not a certificate: a system's own procedures "must include a clear definition of the criteria to be used to verify that the memory is sanitized and must identify all forms and records that need to be completed". There is no fixed cycle; sign-off happens each time memory is purged, destroyed, or a device completes First Article Test, and whether a given result is acceptable is a decision for the national security authority behind the programme, never for this page.

What AEDP-03 references

AEDP-03 is promulgated to NATO nations under STANREC 4750, the Standardization Recommendation that carries it as its cover, and it ties itself directly to STANAG 4575, the NATO Advanced Data Storage Interface: a Removable Memory Module is defined against "the STANAG 4575 interface in a STANAG 4575 compliant system". For the cryptography behind cryptographic erase, it points to NIST's published Special Publications on media encryption, sanitization and key generation, and to NATO's own INFOSEC directives and the AAP-6(V) glossary for its declassification and downgrade terms, rather than restating any of them.

How we help

AEDP-03 is an operational and technical publication, not a management system a supplier implements in software. The sanitization act itself - choosing and running the right procedure for a given device, and confirming a key is destroyed or an overwrite verified - happens in the day-to-day handling of the equipment, under a Security Officer's authority, not inside a compliance tool. What evidencing this kind of guidance involves in practice is the paperwork around that handling: a documented sanitization procedure for each device type in service, records of who performed and who verified each action, training records for the personnel authorized to carry it out, and the completed forms a Security Officer needs before declaring memory sanitized or declassified.

That is the kind of evidence discipline ComplyTrain supports generally: a controlled place to hold procedures, training records and completed sanitization or destruction records, organized so they are ready whenever a Security Officer, an auditor or a customer asks for them.

What ComplyTrain does not do: it does not perform sanitization, verify that a device's key or data is actually gone, or decide which sanitization level or method applies to a given system. Those stay technical and security judgements for the programme's Security Officer and the national security authority behind them.

Which sanitization requirements actually apply to a given programme or contract is set by national policy and the customer's own security requirements, not by us. See what else sits alongside AEDP-03, including STANAG 4575, in the standards explorer, and talk to us about the evidence trail behind a sanitization or destruction programme.

Standards it references

Questions

Is AEDP-03 mandatory for a NATO supplier?

No. AEDP-03 is guidance, not a rule that binds on its own: the document says national requirements may supersede it, and it is promulgated to NATO nations as a recommendation under STANREC 4750, not a ratified STANAG. Whether it applies to a particular programme or contract is a decision for the national security authority and programme involved, not something this page can state generally.

Does AEDP-03 tell me which sanitization method to use for my device?

No. It sets out three sanitization levels and separate procedures for FLASH memory, magnetic disk and RAID systems, and solid state disks, but which one applies to a given device, and with what parameters, is a decision the programme's Security Officer makes under national policy. AEDP-03 itself places that judgement with the user, customer, programme or security manager, not with the document.

What is the difference between Clear, Purge and Destroy?

Clear is a verified erase of the storage element suited to routine reuse. Purge applies techniques that make recovery infeasible even with laboratory methods, typically an overwrite or cryptographic erase followed by verification. Destroy is permanent physical destruction of the media, reserved for end of life or an emergency.

Can cryptographic erase alone sanitize a drive?

Only under specific conditions. AEDP-03 says cryptographic erase should only be used when all data on the device has already been automatically encrypted, and verification that the encryption key is actually destroyed is still required afterward.

Who signs off that a device has been sanitized?

The programme's own Security Officer, who assesses the risk of declaring the memory element "declassified" once it has been purged or destroyed and confirms the required procedures and documentation are complete. There is no external certification body involved.