ISO 27001A.7 — Storage media
A.7.10
Storage media
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Manage storage media through its lifecycle according to classification and handling requirements.
Points of focus
- Classify media handling
- Encrypt portable media if allowed
- Track chain of custody
- Secure disposal or destruction
Implementation notes
Default deny USB storage via MDM. Prefer cloud-native backups. When retiring office PCs, use certified wipe/destruction vendors and keep certificates. Assign a named owner in the SoA, tie operating evidence to media handling procedure, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Show disposal certificates and MDM USB restrictions. Interview IT about last disk retirement.
Evidence auditors typically request:
- Media handling procedure
- Destruction certificates for retired disks
- Encryption requirements for removable media
- Ticket samples for media disposal
Common gaps
- Old hard drives in drawers
- Untracked USB drives
- Cloud snapshots copied to unencrypted disks
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.10 | This control |
| SOC 2 | CC6.5 | Related SOC 2 themes (CC6.5) — map in your crosswalk; not identical requirements. |
| GDPR | Article 32 | Related GDPR themes (Article 32) — map in your crosswalk; not identical requirements. |
| HIPAA | §164.310(d)(2) | Related HIPAA themes (§164.310(d)(2)) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.10)
Frequently Asked Questions
Logical storage is covered under technological controls; A.7.10 focuses on physical media.
Use vendor-appropriate purge/destroy methods; document the method.
Only after approved sanitization aligned to classification.
Even without owned data centers, storage media still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with media handling procedure, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.