ISO/IEC 27001:2022 Annex A · Control 7.10
Storage Media: A Practical Implementation Guide
Control removable and fixed media from acquisition through use, transport, reuse and destruction.
This control concerns managing storage media according to classification and handling requirements.
What should the control achieve?
- Media is inventoried where risk requires.
- Use and movement follow authorization.
- Sensitive media is encrypted and securely stored.
- Reuse and disposal prevent data recovery.
Step-by-step implementation
Define media categories
Identify removable, backup, endpoint, mobile and embedded media.
Restrict use
Disable or limit removable media and approve justified exceptions.
Protect storage and transport
Use encryption, locked storage, packaging and custody records.
Track lifecycle
Record issue, location, transfer, retention and return for sensitive media.
Sanitize for reuse
Select verified clearing method based on media and classification.
Destroy and evidence
Use approved destruction and retain certificates or witness records.
What this could look like in practice
USB storage is blocked by default. Approved encrypted devices have assigned custodians and expiry. Retired SSDs are sanitized with a validated method or physically destroyed when verification is not possible.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Issue | Approved encrypted media is assigned to a user. | Media register |
| Transport | Tamper-evident packaging and tracking protect backup media. | Custody record |
| Reuse | Sanitization is verified before reassignment. | Wipe report |
| Destruction | Approved vendor provides serialized certificate. | Destruction certificate |
Implementation evidence
- Media policy
- Media inventory
- Technical restrictions
- Exception approvals
- Encryption evidence
- Transfer logs
- Sanitization records
- Destruction certificates
Useful metrics
- Unauthorized media detections
- Media exceptions expired
- Sanitization failures
- Inventory discrepancies
Common mistakes
- Assuming deletion or formatting erases data.
- Ignoring storage embedded in printers and network devices.
- Sending unencrypted backups off-site.
- Using destruction certificates without serial reconciliation.
- Stockpiling retired media.
Questions an auditor may ask
- Which media use is permitted?
- How is sensitive media tracked?
- Show verified sanitization.
- How are destruction vendors controlled?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.