Request to disposal, gate by gate — what each stage captures, how each one fails, and why custody is the whole game.
Hardware asset management is a custody discipline. This episode walks the full lifecycle gate by gate — request, procure, receive, deploy, maintain, recover, dispose — and applies the same three questions at every stage: what is this gate, what data has to be captured here, and how does it typically fail?
Part two moves to the end of life, where the risk concentrates: data sanitization under NIST SP 800-88 Revision 2, what R2v3, e-Stewards, and NAID AAA certifications actually mean when you're selecting an ITAD vendor, the real economics behind refresh cycle decisions, and ghost assets — the machines your records insist you still own.
If your inventory can't survive a simple question about where a specific laptop is today, this is the episode that fixes it.
IN THIS EPISODE
- The seven gates of the hardware lifecycle: request, procure, receive, deploy, maintain, recover, dispose
- What data has to be captured at each gate, and how each one typically fails
- Ghost assets: why your records insist you own machines that left two years ago
- Refresh cycle economics, and what the failure-rate data actually supports
- Data sanitization under NIST SP 800-88 Revision 2, and why Revision 1 is withdrawn
- Choosing an ITAD vendor: what R2v3, e-Stewards, and NAID AAA actually certify
- Why degaussing and multi-pass overwriting are the wrong answer for modern flash media
- Custody as the organizing principle behind every hardware asset decision
CHAPTERS
- (00:03) - HAM Lifecycle Overview
(01:40) - Request and Approval(02:48) - Procurement Records(04:00) - Receiving the Asset(05:01) - Deployment and Assignment(06:22) - Maintenance Insights(07:32) - Asset Recovery(09:03) - Secure Disposal(12:59) - Refresh Strategy(14:26) - Ghost and Zombie Assets(15:36) - Library Analogy(16:19) - Custody Discipline
TRANSCRIPT
Click here to view the episode transcript.
SOURCES & FURTHER READING
NIST SP 800-88 Rev. 2, Guidelines for Media Sanitization (current standard, September 2025)
https://csrc.nist.gov/pubs/sp/800/88/r2/final
Full text (PDF)
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r2.pdf
IEEE 2883 — Standard for Sanitizing Storage
https://standards.ieee.org/ieee/2883/10277/
SERI — R2v3 standard and certified facility directory
https://sustainableelectronics.org
e-Stewards certified recycler directory
https://e-stewards.org/find-a-recycler/
i-SIGMA — NAID AAA certification
https://isigma.org
Note: NIST SP 800-88 Revision 1 (2014) was withdrawn and superseded in September 2025. Much of the ITAD guidance circulating online still cites the withdrawn version.
ABOUT THE SHOW
Operational ITAM is a podcast about the unglamorous machinery of enterprise technology — hardware and software asset management, licensing, audit defense, SaaS governance, and the money quietly leaking out of all of them.
Bill Van Nort has led IT asset management, end-user computing, IT operations, and workplace technology at large organizations across banking, mortgage, and automotive. He has reclaimed millions in software spend and survived audits from the biggest publishers on the planet.
Consulting enquiries and listener case files: operationalitam.com