Storage Media - ISO 27001 Annex A Control
ISO 27001 Annex A 7.10
Removable storage walks information out of the building - manage it like the asset it is.
ISO 27001 Annex A 7.10 - Storage Media
Storage media covers a wider range than people sometimes assume. USB drives, external hard disks, optical media, backup tapes, removable internal drives, memory cards, and the storage components of decommissioned equipment all carry information that may need protection through the device's full lifecycle. The control asks for that lifecycle to be managed deliberately.
Acquisition matters because storage choices affect what is possible later. Encrypted media is straightforward to handle securely. Unencrypted media is harder. Approved devices can be tracked. Random USB drives bought by staff cannot. The organisation's policy should set out which devices are approved and how new storage media enters service.
Use, transportation and disposal each carry their own risks. Use needs access controls and logging that match the data sensitivity. Transportation needs encryption, secure carriage, and tracked custody for anything sensitive. Disposal needs reliable destruction or sanitisation that prevents data recovery, with evidence retained showing what was destroyed and how.
The disposal end of the lifecycle is where most organisations have to be most careful. A drive that has been "wiped" using the operating system delete function still contains recoverable data. Effective disposal needs either physical destruction (shredding, degaussing) or proper sanitisation tools that overwrite the data multiple times. We use a certificated disposal supplier and keep the destruction certificates as evidence.
The simplest gap to find is unencrypted storage media in active use. Old USB sticks held by staff "for backups". External drives in drawers that no one can quite remember the contents of. The mitigation is twofold - reduce the population of unmanaged media, and ensure that what remains is encrypted by default so the data is protected even if the device is lost.
Practical Compliance Guidance
Storage media management is described in the IMS1 Manual in Section 8.3 on IT equipment and section 8.5 alongside the Information Security Policy. The equipment register tracks media assignments and disposal.
| alphaZ document | How to use it |
|---|---|
| ISO 27001 Toolkit | The full alphaZ ISO 27001 toolkit including the IMS1 Manual, policies, procedures, registers and audit checklists. |
Note - all the above files can be downloaded with an alphaZ subscription.
