Skip to content
compliancebase
ISO 27001A.7 — Secure disposal or re-use of equipment

A.7.14

Secure disposal or re-use of equipment

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Ensure items of equipment containing storage media are verified as free of sensitive data or securely overwritten prior to disposal or re-use.

Points of focus

  • Inventory equipment with storage
  • Sanitize before reuse
  • Destroy or wipe before disposal
  • Keep certificates

Implementation notes

Retire via ticket: revoke access, wipe or destroy storage, update inventory. Prefer crypto-erase on modern SSDs with documented method. Keep certificates for regulated customers. Assign a named owner in the SoA, tie operating evidence to disposal/reuse procedure, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Show three retired assets with wipe/destroy evidence matching inventory dates.

Evidence auditors typically request:

  • Disposal/reuse procedure
  • Wipe/destruction certificates
  • Asset retirement tickets
  • MDM retirement checklist

Common gaps

  • Sold laptops without wipe
  • Cloud hardware RMAs with disks intact
  • No verification step

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.7.14This control
SOC 2CC6.5Related SOC 2 themes (CC6.5) — map in your crosswalk; not identical requirements.
GDPRArticle 32Related GDPR themes (Article 32) — map in your crosswalk; not identical requirements.
HIPAA§164.310(d)(2)(i)Related HIPAA themes (§164.310(d)(2)(i)) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Follow MDM retirement that cryptographically erases; verify MDM reports success.

Purge storage per vendor guidance before return.

Volume snapshots/disks need logical disposal (A.8.10); physical media is the CSP's control.

Even without owned data centers, secure disposal or re-use of equipment still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with disposal/reuse procedure, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above