Chain of custody for data destruction
The certificate is the headline. The chain of custody is the evidence behind it — and it's what actually holds up under scrutiny.
A chain of custody is the unbroken record of each drive's journey — from the moment it's identified, through sanitisation, to its final disposition. If a certificate is a claim, the chain of custody is the evidence that the claim describes something real.
What a chain of custody records
- Identification — serial number, model, and the system it came from.
- Method — the exact sanitisation technique applied and its NIST 800-88 outcome.
- Status — the final state of each drive: erased, or flagged for destruction.
- Time — when the work happened, tied to one job.
The role of the Chain of Custody ID
tScrub ties a job together with a Chain of Custody ID (COCID) — a single identifier you set at the start of a run. Every drive in that run references it, which means one ID links a whole batch of drives to one report and one certificate. That's what turns "we wiped some drives" into "here is the exact set of drives, and what happened to each."
Why it matters in practice
When a regulator, client, or auditor asks a question — "what happened to the drives from server X?" — the chain of custody lets you answer with serial numbers rather than a shrug. It closes the gap between your erasure policy and a specific, demonstrable event.
Keeping it defensible
- Use COCID conventions your team recognises (ticket numbers, asset IDs).
- Keep the source report files alongside the certificate.
- Prefer signed reports for drives leaving your control — they're tamper-evident, so the chain can't be quietly altered.
- Record SMART data where available, as supporting evidence of drive condition.
FAQ
Is a chain of custody the same as a certificate?
No. The certificate is the formal summary document; the chain of custody is the underlying per-drive record. A good certificate references a chain of custody (its COCID), not the other way around.
Can one COCID cover multiple drives?
Yes — that's the point. One COCID binds all the drives in a job into a single auditable unit, and one certificate can cover them all.