S 2.400 Secure withdrawal from operation of printers, copiers, and all-in-one devices

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Administrator

When printers, copiers, all-in-one devices, or individual components of such devices are withdrawn from operation or replaced, all security-related information must be deleted from the devices. This applies especially when the components will be disposed of or given to third parties. Examples include when the device is sold, returned after expiration of the lease, replaced by the manufacturer, or sent to a corresponding service company for repair. However, all information requiring protection must be deleted from the devices even when the devices will be reused internally or scrapped.

Depending on the type of device and what it is used for, the following security-related information may be stored on it, for example:

Before withdrawing devices from operation or handing them over to third parties, the data on the internal storage device must be deleted. If the hard disk can be removed, then it is recommended to erase the hard disk separately. After the data on the storage device have been deleted, it must be checked to see if deletion was also successful.

The deletion procedure depends greatly on the type and use of the particular device.

If information particularly critical to security is stored on the device and it cannot be guaranteed with sufficient security that the data really were deleted, then it may be necessary to physically destroy the storage device or make it unusable.

Review questions: