Start a free trial
Menu

STANREC 4750

STANREC 4750 memory systems sanitization guide

NATO nations weighing AEDP-3 for sanitizing ISR system storage media, and the organisations handling that media under a customer or national security requirement

STANREC 4750 is NATO's non-binding recommendation that nations use AEDP-3 to purge and sanitize FLASH, SSD and magnetic disk storage in ISR systems; what counts as adequate sanitization is a national security authority's decision, not this document's.

Edition
1
Published
2014-12-20

What it is

A recommendation, not an obligation

STANREC 4750 is a NATO Standardization Recommendation covering advanced data storage technology memory systems sanitization. Like every STANREC, it stops short of a STANAG's ratified commitment: the document states plainly that it "is a non-binding document employed on a voluntary basis and does not require commitment of the nations to implement the standards which are listed in it." Nations are free to use the practice it points at, or not, and nothing in the STANREC itself creates an obligation a supplier signs up to directly.

What it recommends, and what it does not

The stated aim is "to list recommended practices regarding: proper data purge and sanitization techniques for advanced technology memory systems," and the document is specific about which devices it has in view: "FLASH solid-state, Solid State disk (SSD) and advanced magnetic disk and disk array storage devices used in ISR systems." What it recommends nations use is a single named publication, "AEDP-3, Edition C, Version 1", the Allied Engineering Publication that carries the sanitization guide this STANREC's own title borrows. STANREC 4750 itself sets out no purge method, no overwrite count and no parameter for any of these device types. That content is AEDP-3's, not this cover document's, and this page has not read AEDP-3.

Superseded arrangement

This edition "supersedes the following document: AEDP-3 edition 2, 8 September 2009." The earlier arrangement pointed at an older edition of the same underlying publication; this STANREC updates the recommendation to Edition C, Version 1.

Review, and how changes reach it

STANREC 4750 "is to be reviewed at least once every three years," with the outcome recorded in NATO's Standardization Document Database. Outside that cycle, "nations and NATO bodies may propose changes, at any time, through a standardization proposal to the tasking authority" - the Joint Capability Group on ISR, which supervises this STANREC.

Where the actual sanitization guidance lives

Two further documents are named for context: STANAG 4575, Edition 4 (NATO Advanced Data Storage Interface), and NIST Special Publication 800-88, Sanitization Guidelines, published by the US National Institute for Standards and Technology. Neither is a requirement of this STANREC; both are named as related reading. The document that actually carries the sanitization techniques is AEDP-03, the publication STANREC 4750 recommends. What counts as adequate sanitization for a given classification of data is, in every case, a decision for the national security authority responsible for that data, not something this STANREC, AEDP-3, or a vendor sets.

How we help

STANREC 4750 gives an organisation nothing to configure in software: it names AEDP-3 as the practice to follow for sanitizing ISR system storage media, and the technique itself sits inside that publication, carried out by qualified personnel under a method the responsible national security authority accepts.

What is left is the ordinary discipline of evidencing that the work happened: recording which sanitization method a procedure specifies and why, holding the record of each sanitization action carried out against a given piece of media, training the people who do that work, and keeping the documentation a customer's quality representative or an internal audit would ask to see. ComplyTrain gives a place to hold that documentation and keep training records for the people doing the work current.

ComplyTrain does not perform or verify a sanitization action, and it does not decide which method is adequate for a given classification level - that determination stays with the national security authority responsible for the data. Which standards a given contract actually invokes, AEDP-3 included, is set by the contract and the customer's quality clause, not by this page. Our standards explorer shows what sits alongside STANREC 4750 - if a tender or a security requirement has put this in front of you, we're glad to talk it through.

Standards it references

Questions

Is STANREC 4750 mandatory?

No. A STANREC is a recommendation, not an agreement: nations are free to use the standard it names without a ratification obligation. Whether AEDP-3 applies to a given programme is a question for that programme's contract or national security policy, not for this document.

What does STANREC 4750 actually recommend?

It recommends that nations use AEDP-3, Edition C, Version 1, for purging and sanitizing FLASH, SSD and magnetic disk storage devices used in ISR systems. The STANREC names the publication; it does not itself contain a sanitization procedure.

Does STANREC 4750 say how to sanitize a device?

No. It states its aim and the device types in scope, and points to AEDP-3 for the technique. Neither document available here sets out a method a reader should apply without the responsible national security authority's own decision on what is adequate for the classification involved.

What is the difference between a STANREC and a STANAG?

A STANAG is an agreement nations ratify and commit to implement. A STANREC recommends a standard without that obligation - nations are invited to use it, and nothing requires them to.

Does this edition replace an earlier one?

Yes. STANREC 4750 supersedes the arrangement built around AEDP-3 edition 2 of 8 September 2009, updating the recommendation to AEDP-3, Edition C, Version 1.