Arizona’s P8250 and S8250 are part of Arizona’s Information Security Policies, Standards, and Procedures (PSPs), a framework in which “P” denotes POLICY and “S” denotes the corresponding STANDARD. They belong to the P8000 series, which is now hosted by the Arizona Department of Homeland Security. The current P8250 policy is revision 5.0, effective January 30, 2025, while S8250 is revision 1.1, effective April 5, 2024. The P8000 series provides business principles, best practices, technical standards, and implementation guidance for state information security.
These policies refer to major federal security and privacy frameworks, including NIST 800-53, HIPAA, PCI DSS, and IRS Publication 1075. The policies establish requirements for protecting information and media within the Arizona state information environment. Media protection is a core part of this framework because improperly handled or disposed media, whether digital drives, backup tapes, or paper records, remains one of the most common sources of data breaches and compliance failures. P8250 and S8250 therefore address media protection across its lifecycle, with specific requirements for handling, transporting, sanitizing, and disposing of media.
Who Must Comply With Arizona P8250 and S8250?
Arizona P8250 and S8250 apply to all Budget Units (BUs) as defined in A.R.S. § 18-101(1). A BU is a department, commission, board, institution, or other agency of the state that receives, expends, or disburses state funds or incurs obligations of the state. P8250 applies to all agency systems, while additional policy statements apply based on the type or classification of information involved. S8250 applies to all state information systems, with statements marked “(P)” required for systems categorized as ‘Protected.’
- Protected systems (P): Applies to any system classified as protected.
- Payment card data (P-PCI): Applies to systems handling cardholder or payment card industry data.
- Health information (P-PHI): Applies to systems that contain protected healthcare information.
- Federal tax data (P-FTI): Applies to systems holding federal taxpayer information.
Note: Information owned or controlled by the U.S. federal government must follow federal classification authority and protection requirements, rather than Arizona's own framework.
How Does Arizona P8250 Address Media Protection?
P8250 requires specific media protection controls covering different stages of the media lifecycle. These controls include media access, marking, storage, inventory, transport, sanitization, and use. These are defined below:
-
Media Access: Only authorized individuals may access the digital or non-digital media. (Refer NIST 800-53 MP-2; HIPAA 164.308(a)(3)(ii)(A); PCI DSS 9.6; IRS Pub 1075)
-
Media Marking: Media containing confidential information must be labeled according to the BU policies and procedures indicating distribution limits, handling instructions, and applicable security markings. Removable digital media is exempt from this requirement as long as it stays within a controlled environment. (Refer NIST 800-53 MP-3; PCI DSS 9.6.1; IRS Pub 1075)
-
Media Storage: Media containing confidential information must be physically controlled and securely stored within controlled areas. (Refer NIST 800-53 MP-4; ARS 39-101; PCI DSS 9.5, 9.7; IRS Pub 1075)
-
Media Inventory: BUs must maintain inventory logs (Records) of all digital media containing confidential information and conduct a full inventory check at least once a year. (Refer to PCI DSS 9.7.1)
-
Media Transport: Media containing confidential information must be protected and controlled whenever it is moved outside a controlled area using secure methods and encryption. For systems with protected healthcare information, agencies must maintain a record of the media’s movement (Chain of Custody). Separately, before moving equipment, agencies must create a retrievable backup of the confidential data and store that backup in a secure location, reviewing its security at least annually. (Refer NIST 800-53 MP-5; PCI DSS 9.6; IRS Pub 1075)
-
Media Sanitization: Before disposal, release of control, or reuse, media containing confidential information must be sanitized using the defined techniques set out in the Media Protection Standard (S8250). (Refer to NIST SP 800-53 MP-6, HIPAA 164.310(d)(2)(i)-(ii), IRS Publication 1075, and PCI DSS Requirements 9.8, 9.8.1, and 9.8.2.)
-
Secure Storage: Materials awaiting destruction must be kept in secure storage containers. (Refer to PCI DSS 9.8.1)
-
Verify Sanitization: For systems holding federal taxpayer information, sanitization and disposal actions must be reviewed, approved, tracked, documented, and verified. (Refer NIST 800-53 MP-6(1); IRS Pub 1075)
-
Media Use: Agencies must restrict which types of digital media can be used on specific systems, and must prohibit portable storage devices that have no identifiable owner from being used on agency systems. (Refer to NIST 800-53 MP-7; IRS Pub 1075; PCI DSS 5.3.3)
What Sanitization Methods Does Arizona S8250 Specify?
S8250 mentions specific sanitization requirements for media installed, connected, or used within a state information system. It defines three core techniques that may be applied to media being reissued, reused, or discarded:
- Clear: Overwrites storage space on the media with non-confidential random data, covering both the logical storage space and all other addressable locations.
- Purge: Renders sanitized data unrecoverable against laboratory recovery methods, using techniques like degaussing or a firmware-based Secure Erase command (for ATA drives).
- Destroy: Ensures the media can no longer be reused as originally intended, making the information virtually impossible or prohibitively expensive to recover.
S8250 section 6.1.9 requires media-specific sanitization techniques to be followed as per the standard. The applicable sanitization methods include Overwrite, Secure Erase, Degauss, Manufacturer’s Reset, or physical destruction. (Refer to Table 1.1 of S8250 for the complete media-specific requirements.)
Sanitization Through Approved Products/Operators
S8250 requires sanitization techniques to be performed using an approved product or a licensed operator. The Arizona standard specifies the applicable product approval references based on the sanitization method:
- Overwriting shall be performed by a product on the National Information Assurance Partnership, Common Criteria Evaluation & Validation Scheme’s Product Compliant List. (Example: Common Criteria Certified BitRaser qualifies Arizona criteria for approved product)
- Degaussing shall be performed by a product on the National Security Agency’s Evaluated Products List (NSA’s EPL).
- Shredders must meet NSA/CSS specifications for high-security crosscut paper shredders.
- Disintegrators must meet NSA/CSS specifications for high-security disintegrators.
- Grinding equipment must meet NSA/CSS specifications for optical media destruction devices.
What is the Data Sanitization Process Under Arizona S8250?
Budget Units can refer to the diagram below, together with the guidance in this standard, to determine the correct sanitization process for a given piece of media. The appropriate process depends on two factors:
- Sensitivity of the data
- Whether the media remains under the BU's control.
S8250 considers media to be under BU control when it is being used within the BU environment or certain approved maintenance arrangements. Media exchanged for warranty, cost rebate, or other purposes and not returned to the BU is not considered under BU control.

Figure 1.1: Data Sanitization and Disposition Process
Source: Arizona Statewide Standard S8250
Further, the statewide standard requires covered entities to verify the sanitization process and document the result.
Verification & Documentation Requirements of S8250
Budget Units (BUs) must verify the sanitization and disposal process by testing a representative sample of sanitized media and having the results independently verified by personnel not involved in the process.
- Equipment calibration: Tools must be used, calibrated, tested, and maintained according to the manufacturer's instructions.
- Personnel training: Anyone operating the equipment must be competent to perform the sanitization function correctly, and must follow the manufacturer's operating guidelines.
The BU shall maintain a record of its sanitization. Sanitization documentation shall include:
- Media Sanitized
- Date sanitization occurred
- Method used for sanitization
- Final disposition of the data
If a BU uses a third-party service for media or document destruction, the media must be stored securely until it is purged or destroyed.
How Can BitRaser Help Comply with Arizona Statewide Standard and Policy?
For state agencies, Budget Units, and contractors seeking to comply with Arizona P8250 & S8250, securely handling, storing, sanitizing, and disposing of digital and non-digital media is essential. Using a certified data erasure solution such as BitRaser Drive Eraser can help organizations address the sanitization requirements while supporting data confidentiality and integrity.
The Common Criteria-certified software helps meet the approved product criteria that support recommended techniques like Clear and Purge.
Reach out to our sales team to learn more: [email protected].