ISO/IEC 27001:2022 Annex A · Control 7.14
Secure Disposal or Re-use of Equipment: A Practical Implementation Guide
Remove sensitive data and organizational identifiers before equipment is discarded, sold, returned or reassigned.
This control concerns verifying that information and licensed software have been removed or securely overwritten before equipment disposal or reuse.
What should the control achieve?
- Disposition is authorized and recorded.
- Data-removal methods are risk and media appropriate.
- Reuse verifies a trusted configuration.
- Destruction and vendor handling are evidenced.
Step-by-step implementation
Define disposition routes
Cover internal reuse, return, resale, donation, recycling and destruction.
Identify data-bearing components
Include drives, flash storage, printers, phones, network devices and embedded controllers.
Select sanitization method
Use clearing, cryptographic erase, purging or physical destruction according to risk and technology.
Verify results
Use supported tools, logs, sampling and independent checks for sensitive assets.
Control third parties
Assess vendors, custody, transport, certificates and downstream processing.
Update records
Reconcile serial numbers, licenses, ownership and final status.
What this could look like in practice
Retired laptops are inventoried by serial number, cryptographically erased with logged verification and rebuilt from the approved baseline for internal reuse. Failed drives are shredded by an approved vendor under witnessed custody.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Internal reuse | Sanitization is verified before baseline rebuild. | Wipe and build record |
| Lease return | Data removal and asset reconciliation precede shipment. | Return checklist |
| Destruction | Serialized media follows secure transport to approved destruction. | Certificate |
| Embedded storage | Printer and network-device memory are included. | Device checklist |
Implementation evidence
- Disposal and reuse procedure
- Asset disposition approvals
- Sanitization standards
- Wipe logs
- Verification records
- Chain of custody
- Vendor due diligence
- Serialized destruction certificates
Useful metrics
- Disposed assets with matched evidence
- Sanitization failures
- Assets awaiting disposition
- Certificates with serial discrepancies
Common mistakes
- Using simple file deletion.
- Forgetting embedded and removable storage.
- Trusting vendor certificates without reconciliation.
- Selling equipment with organizational labels or licenses.
- Reusing equipment without secure baseline.
Questions an auditor may ask
- How is the sanitization method selected?
- Show serial-level evidence.
- How are disposal vendors assessed?
- What happens when wiping fails?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.