ISO 27001A.7 — Secure disposal or re-use of equipment
A.7.14
Secure disposal or re-use of equipment
ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026
Objective
Ensure items of equipment containing storage media are verified as free of sensitive data or securely overwritten prior to disposal or re-use.
Points of focus
- Inventory equipment with storage
- Sanitize before reuse
- Destroy or wipe before disposal
- Keep certificates
Implementation notes
Retire via ticket: revoke access, wipe or destroy storage, update inventory. Prefer crypto-erase on modern SSDs with documented method. Keep certificates for regulated customers. Assign a named owner in the SoA, tie operating evidence to disposal/reuse procedure, and sample the control during internal audit before Stage 2 fieldwork.
Audit tip: Show three retired assets with wipe/destroy evidence matching inventory dates.
Evidence auditors typically request:
- Disposal/reuse procedure
- Wipe/destruction certificates
- Asset retirement tickets
- MDM retirement checklist
Common gaps
- Sold laptops without wipe
- Cloud hardware RMAs with disks intact
- No verification step
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.7.14 | This control |
| SOC 2 | CC6.5 | Related SOC 2 themes (CC6.5) — map in your crosswalk; not identical requirements. |
| GDPR | Article 32 | Related GDPR themes (Article 32) — map in your crosswalk; not identical requirements. |
| HIPAA | §164.310(d)(2)(i) | Related HIPAA themes (§164.310(d)(2)(i)) — map in your crosswalk; not identical requirements. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.7.14)
Frequently Asked Questions
Follow MDM retirement that cryptographically erases; verify MDM reports success.
Purge storage per vendor guidance before return.
Volume snapshots/disks need logical disposal (A.8.10); physical media is the CSP's control.
Even without owned data centers, secure disposal or re-use of equipment still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.
Start with disposal/reuse procedure, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.