Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 7.10

Storage Media: A Practical Implementation Guide

Control removable and fixed media from acquisition through use, transport, reuse and destruction.

This control concerns managing storage media according to classification and handling requirements.

Practical interpretation: Media includes drives, tapes, removable devices and embedded storage. Risks remain even when media is obsolete, damaged or sent for repair.

What should the control achieve?

  • Media is inventoried where risk requires.
  • Use and movement follow authorization.
  • Sensitive media is encrypted and securely stored.
  • Reuse and disposal prevent data recovery.

Step-by-step implementation

1

Define media categories

Identify removable, backup, endpoint, mobile and embedded media.

2

Restrict use

Disable or limit removable media and approve justified exceptions.

3

Protect storage and transport

Use encryption, locked storage, packaging and custody records.

4

Track lifecycle

Record issue, location, transfer, retention and return for sensitive media.

5

Sanitize for reuse

Select verified clearing method based on media and classification.

6

Destroy and evidence

Use approved destruction and retain certificates or witness records.

What this could look like in practice

USB storage is blocked by default. Approved encrypted devices have assigned custodians and expiry. Retired SSDs are sanitized with a validated method or physically destroyed when verification is not possible.

ActivityPractical implementationEvidence
IssueApproved encrypted media is assigned to a user.Media register
TransportTamper-evident packaging and tracking protect backup media.Custody record
ReuseSanitization is verified before reassignment.Wipe report
DestructionApproved vendor provides serialized certificate.Destruction certificate

Implementation evidence

  • Media policy
  • Media inventory
  • Technical restrictions
  • Exception approvals
  • Encryption evidence
  • Transfer logs
  • Sanitization records
  • Destruction certificates

Useful metrics

  • Unauthorized media detections
  • Media exceptions expired
  • Sanitization failures
  • Inventory discrepancies

Common mistakes

  • Assuming deletion or formatting erases data.
  • Ignoring storage embedded in printers and network devices.
  • Sending unencrypted backups off-site.
  • Using destruction certificates without serial reconciliation.
  • Stockpiling retired media.

Questions an auditor may ask

  • Which media use is permitted?
  • How is sensitive media tracked?
  • Show verified sanitization.
  • How are destruction vendors controlled?
Implementation test: Select retired and active media and trace authorization, custody, protection, data classification and final disposition.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.