- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-04-2019 07:45 AM
I am finding conflicting, perhaps outdated information on the sanitization (or zeroize or declassify) of cisco switches. Is it true that the 5900 series routers are the only model that support the "service declassify" command? Or do any other products support this? More specifically the 2960-L switch?
If not, is there a comparable procedure to zeroize this switch to meet government sanitization standards?
Solved! Go to Solution.
- Labels:
-
Physical Security
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-04-2019 09:05 AM
Hi there,
I have only ever come across the zeroize command on some older routers, certainly not on a 2960. Arguably just formatting the flash on the 2960 should be sufficient as it is not removable.
Regarding moving your switches, provide the destination room has the same security classification or above you should be fine. It is moving items to lower classifications that you cannot do.
cheers,
Seb.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-04-2019 08:07 AM
Hi there,
What classification has the device been used at?
Using UK HMG classifications at Official all non-volatile memory must be formatted and removed. The switch can then be sent for recycling.
At Secret, all non-volatile memory must be formatted and removed and sent for destruction via approved suppliers on site. Likewise the switch must be sent to approved suppliers for shredding.
At TS and above nothing can leave the site. The entire unit must be shredded on site. This involves removing the PCB for shredding, the metal chassis can be sent for scrap.
cheers,
Seb.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-04-2019 08:23 AM
Several units will be at varying levels of security. We were hoping/needing to just move units from one room to another and would need to sanitize in order to do that. So you're saying for sure there is no zeroize feature similar to what's on the 5900 series router?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-04-2019 09:05 AM
Hi there,
I have only ever come across the zeroize command on some older routers, certainly not on a 2960. Arguably just formatting the flash on the 2960 should be sufficient as it is not removable.
Regarding moving your switches, provide the destination room has the same security classification or above you should be fine. It is moving items to lower classifications that you cannot do.
cheers,
Seb.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-04-2019 09:17 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-04-2019 03:32 PM
Without knowing much about your site, you should be safe enough moving items around a building within a site, so long as you apply the two-man rule and don't leave the devices unattended during transit between the secured rooms.
cheers,
Seb.
