What is ISO 27001 Annex A 7.10 – Storage Media?
ISO 27001 Annex A 7.10 – Storage Media requires organizations to manage storage media throughout its lifecycle so that information stored on the media is protected from unauthorized access, modification, loss, damage, or disclosure.
Storage media includes physical and removable devices that can store organizational information.
Examples include:
- USB flash drives
- External hard drives
- SSDs
- CDs/DVDs
- Backup tapes
- Memory cards
- Mobile device storage
- Laptop and desktop hard drives
- Server drives
- Backup media
- Removable storage devices
- Printed or physical media where applicable
- Other portable or removable information storage
The organization should consider how storage media is:
Received → Classified → Used → Stored → Transported → Protected → Reused → Disposed
Simple explanation: If information can be stored on a device, the organization should know how that storage media is protected, handled, transported, reused, and securely disposed of.
Why is Annex A 7.10 Important?
Storage media can contain highly sensitive information.
For example, a single USB drive could contain:
- Customer information
- Employee records
- Source code
- Database exports
- Security reports
- Backup data
- Financial information
- Contracts
- Credentials or configuration files
- Personal information
- Confidential business information
If the media is lost, stolen, copied, improperly reused, or disposed of without proper protection, sensitive information may be exposed.
Common risks
| Risk | Example |
|---|---|
| Loss | Employee loses a USB containing customer data |
| Theft | Laptop containing an unencrypted drive is stolen |
| Unauthorized access | External drive is connected to an unauthorized computer |
| Data leakage | Database export is copied to removable media |
| Improper disposal | Old hard drive is thrown away without secure erasure |
| Unauthorized copying | Employee copies confidential files to a personal USB |
| Malware | Infected USB introduces malware into company systems |
| Uncontrolled backup | Backup drive is stored without adequate protection |
| Physical damage | Storage media is damaged by fire, water, or heat |
| Unauthorized reuse | Old drive is reassigned without removing previous data |
Simple principle: Protect the information, not just the storage device.
What Does ISO 27001 Annex A 7.10 Require?
The organization should establish appropriate controls for storage media based on:
- Information classification
- Business requirements
- Security risks
- Type of media
- Sensitivity of information
- Where the media is stored
- Who can access it
- Whether it is transported
- Whether it is reused
- Whether it needs to be destroyed
- Legal, regulatory, and contractual requirements
ISO 27001 does not mean that every organization must ban USB drives.
Instead, the organization should determine:
What storage media do we use?
What information can be stored on it?
Who can use it?
How is it protected?
What happens when it is no longer required?
What is Storage Media?
Storage media is any physical or electronic medium capable of storing information.
Common examples
| Storage Media | Example Use |
|---|---|
| USB drive | Temporary file transfer |
| External HDD/SSD | Backup or data transfer |
| Laptop SSD | Operating system and business data |
| Server disk | Application/database storage |
| Backup tape | Long-term backup |
| SD card | Cameras or specialized equipment |
| Mobile storage | Phones/tablets |
| CD/DVD | Legacy archives |
| Removable backup media | Offline backups |
| Encrypted portable drive | Secure transfer of sensitive data |
For a modern SaaS startup, much of the production data may be stored in cloud platforms rather than removable physical media.
However, storage media can still exist through:
- Employee laptops
- Backup systems
- External drives
- Mobile devices
- Developer machines
- Security tools
- Database exports
- Offline backups
- USB devices
Storage Media Lifecycle
A practical approach is to manage storage media through its entire lifecycle:
Acquire → Register → Classify → Authorize → Use → Store → Transport → Monitor → Reuse → Dispose
The organization should determine the appropriate controls at each stage.
Activities Required to Implement Annex A 7.10
1. Identify Storage Media
First, identify what types of storage media are used within the organization.
For example:
- Company laptops
- External hard drives
- USB drives
- Backup drives
- Mobile devices
- Server storage
- Offline backups
- Removable media used by IT teams
Do not limit the assessment to devices owned by the IT department.
Consider how employees, contractors, developers, administrators, and third parties use storage media.
2. Identify What Information is Stored
Determine what types of information can be stored on each medium.
For example:
| Storage Media | Information |
|---|---|
| Employee laptop | Business documents, email, source code |
| Backup drive | Database backup |
| USB drive | Temporary file transfer |
| Mobile phone | Email, messages, business applications |
| External SSD | Security assessment reports |
| Server disk | Application/database information |
This should be connected to Annex A 5.12 – Classification of Information.
3. Define Acceptable Use
Establish clear rules for the use of removable and portable storage.
For example:
- Only company-approved USB devices may be used.
- Personal USB devices should not be used for company information.
- Sensitive information should not be copied to removable media unless authorized.
- Storage devices containing confidential information should be encrypted.
- Unknown USB devices should not be connected to company systems.
- Lost or stolen storage media must be reported immediately.
4. Control Removable Media
Organizations can implement controls such as:
- USB device restrictions
- Endpoint security policies
- Device control software
- Encryption
- Access permissions
- Malware scanning
- Administrator approval
- Data Loss Prevention controls
- Logging where appropriate
The appropriate level depends on the organization’s risk.
A 10-person startup does not necessarily need an expensive enterprise DLP platform simply because ISO 27001 requires storage media controls.
A documented policy combined with endpoint configuration, encryption, employee awareness, and access controls may be appropriate.
5. Protect Sensitive Information on Storage Media
Where sensitive information is stored on portable media, appropriate protection should be applied.
Examples include:
- Full-disk encryption
- Encrypted USB drives
- File-level encryption
- Password protection where appropriate
- Access controls
- Strong authentication
- Secure storage
- Controlled transportation
For example:
Customer database export → encrypted external drive → authorized employee → controlled transfer → secure deletion after use.
6. Control Transportation of Storage Media
Storage media may be physically transported between:
- Offices
- Data centers
- Backup locations
- Customer sites
- Employees
- Suppliers
- Disaster recovery locations
Transportation risks should be considered.
Controls may include:
- Encryption
- Tamper-evident packaging
- Authorized couriers
- Chain-of-custody records
- Secure containers
- Delivery confirmation
- Restricted access
7. Protect Storage Media From Physical Damage
Storage media should be protected from:
- Fire
- Water
- Excessive heat
- Humidity
- Dust
- Physical impact
- Magnetic or electrical risks where relevant
- Theft
- Unauthorized handling
This connects with:
- A.7.5 – Protecting Against Physical and Environmental Threats
- A.7.8 – Equipment Siting and Protection
- A.8.13 – Information Backup
8. Manage Backup Media
If physical media is used for backups, the organization should consider:
- Backup classification
- Encryption
- Access restrictions
- Storage location
- Retention period
- Backup frequency
- Transportation
- Restoration testing
- Physical protection
- Secure destruction
For example:
Production database → encrypted backup → protected backup location → periodic restore test → retention period → secure disposal
9. Manage Reuse of Storage Media
Before storage media is reassigned, the organization should determine whether previous information must be removed.
For example:
An employee leaves the company.
Their laptop is returned.
The laptop is given to another employee.
Simply deleting visible files may not be sufficient for every situation.
The organization should use an appropriate secure sanitization process based on the sensitivity of the information and the technology involved.
10. Secure Disposal of Storage Media
When storage media is no longer required, it should be disposed of securely.
Possible methods include:
- Secure data erasure
- Cryptographic erasure where appropriate
- Physical destruction
- Approved media destruction services
- Certified disposal providers
The appropriate method depends on the sensitivity of the information and the type of media.
Where third parties are used, retain appropriate evidence such as:
- Disposal records
- Destruction certificates
- Asset records
- Vendor details
- Chain-of-custody documentation
Startup Example
Imagine a 40-person SaaS company.
The company uses:
- AWS for production
- Google Workspace
- Company laptops
- Employee mobile phones
- USB drives occasionally
- External SSDs for certain IT activities
- Automated cloud backups
The company does not need to create a complicated media-management program.
A practical approach could be:
Step 1 – Define the policy
Only authorized storage media may be used for company information.
Step 2 – Encrypt laptops
Company laptops use full-disk encryption.
Step 3 – Restrict USB use
USB storage is restricted through endpoint controls where the risk justifies it.
Step 4 – Protect sensitive exports
Database exports or security reports must not be copied to personal USB devices.
Step 5 – Control external drives
Company-approved external drives must be encrypted.
Step 6 – Secure disposal
Old laptops and storage devices go through an approved secure-erasure or destruction process.
Step 7 – Maintain evidence
The organization retains:
- Asset records
- Media disposal records
- Encryption configuration
- Relevant policies
- Employee acknowledgement
- Endpoint configuration evidence
Result:
Identify → Authorize → Protect → Use → Transport → Reuse → Securely Dispose
Storage Media Register
A startup can maintain a simple register.
| Media ID | Type | Owner | Information | Classification | Encryption | Location | Status |
|---|---|---|---|---|---|---|---|
| MED-001 | External SSD | IT | Backup | Confidential | Yes | IT Storage | Active |
| MED-002 | USB | Security | Audit reports | Confidential | Yes | Secure cabinet | Active |
| MED-003 | Laptop SSD | Employee | Business data | Internal | Yes | Employee | Active |
| MED-004 | Backup Drive | IT | Backup data | Restricted | Yes | Backup facility | Retired |
Not every organization needs to register every individual storage component.
The level of inventory should be proportionate to risk and operational requirements.
Removable Media Authorization Matrix
| Activity | Employee | IT Admin | Security | Management |
|---|---|---|---|---|
| Use approved USB | ✓ | ✓ | ✓ | ✓ |
| Copy confidential information | Restricted | ✓ | ✓ | Approval |
| Create database export | No | ✓ | ✓ | Approval |
| Use personal USB | No | No | No | No |
| Dispose of storage media | No | ✓ | ✓ | Approval |
| Authorize exception | No | No | ✓ | ✓ |
The exact authorization model should be adapted to the organization’s size and risk.
Storage Media Risk Assessment
| Risk | Likelihood | Impact | Example Control |
|---|---|---|---|
| USB lost | Medium | High | Encryption |
| Unauthorized USB | Medium | High | Device control |
| Malware via USB | Medium | High | Endpoint protection |
| Backup stolen | Low | High | Encryption + secure storage |
| Improper disposal | Medium | High | Secure destruction |
| Data copied without authorization | Medium | High | Access/DLP controls |
| Media damaged | Low | High | Environmental protection |
| Unauthorized reuse | Medium | High | Secure sanitization |
Storage Media Handling Procedure
A simple procedure can define:
Before use
- Verify authorization
- Verify approved device
- Confirm classification
- Apply encryption where required
During use
- Do not leave media unattended
- Do not connect unknown devices
- Do not copy information unnecessarily
- Follow acceptable-use requirements
During transportation
- Protect against loss
- Use secure packaging
- Maintain authorization
- Use encryption for sensitive information
After use
- Return or securely store media
- Delete temporary information where appropriate
- Update records
- Securely dispose of media when no longer required
Audit Evidence for Annex A 7.10
An auditor may request evidence such as:
Policies and procedures
- Storage Media Policy
- Acceptable Use Policy
- Removable Media Procedure
- Data Classification Policy
- Information Transfer Procedure
- Secure Disposal Procedure
- Asset Management Procedure
Operational evidence
- Storage media register
- Asset inventory
- USB/device control configuration
- Encryption configuration
- Endpoint management reports
- Backup records
- Media transportation records
- Media disposal records
- Destruction certificates
- Secure erasure records
- Exception approvals
- Security awareness training records
Technical evidence
Depending on the environment:
- Endpoint management screenshots
- Device-control configuration
- Encryption status
- DLP policies
- EDR configuration
- USB restrictions
- Mobile device management configuration
Audit Checklist – ISO 27001 Annex A 7.10
| Question | Yes/No | Evidence |
|---|---|---|
| Has the organization identified storage media used to store information? | ||
| Are storage media classified according to information sensitivity? | ||
| Are removable media rules documented? | ||
| Is use of personal storage media controlled? | ||
| Are sensitive storage media appropriately protected? | ||
| Is encryption used where required? | ||
| Is transportation of sensitive media controlled? | ||
| Are backup media protected? | ||
| Is storage media protected from physical/environmental risks? | ||
| Is media reuse controlled? | ||
| Is sensitive information securely erased before reuse? | ||
| Is obsolete media securely destroyed or sanitized? | ||
| Are disposal records maintained where appropriate? | ||
| Are exceptions formally approved? | ||
| Are employees aware of storage media requirements? | ||
| Are controls periodically reviewed? |
Common Mistakes
1. Treating USB drives as the only storage media
Storage media includes much more than USB drives.
Laptops, mobile devices, backup drives and other physical storage should also be considered.
2. Allowing personal USB devices
Employees may copy company information to personal storage devices without authorization.
This creates significant loss-of-control risk.
3. No encryption
Sensitive information stored on portable devices can be exposed if the device is lost or stolen.
4. No secure disposal process
Throwing an old hard drive into normal waste does not demonstrate appropriate information protection.
5. Ignoring backups
Backup media can contain some of the organization’s most sensitive information.
6. No process for lost devices
The organization should define what happens when:
- USB drives are lost
- Laptops are stolen
- Backup media goes missing
- External drives are misplaced
7. Creating excessive bureaucracy
A startup may create a 20-page storage media procedure that nobody follows.
The objective is effective protection, not documentation for its own sake.
8. Assuming cloud storage eliminates the requirement
Cloud storage can reduce the organization’s reliance on physical removable media, but organizations still have:
- Laptops
- Mobile devices
- Local storage
- Backups
- External devices
- Physical records
The organization should assess its actual environment.
Practical Startup Implementation Model
A startup can implement Annex A 7.10 using this model:
1. Identify
Identify storage media used by the organization.
2. Classify
Understand what information can be stored on it.
3. Authorize
Define who can use removable or portable media.
4. Protect
Use encryption, access control and endpoint security.
5. Transport
Protect media when it leaves the organization’s control.
6. Monitor
Monitor relevant use and exceptions where appropriate.
7. Reuse
Securely sanitize media before reassignment.
8. Dispose
Securely erase or destroy obsolete media.
9. Record
Maintain appropriate evidence.
10. Review
Periodically review whether the controls remain appropriate.
Startup formula: Know the media → Know the information → Control the use → Protect the data → Secure the disposal.
Policy vs. Process vs. Evidence
A common ISO 27001 mistake is confusing documentation with implementation.
| Layer | Example |
|---|---|
| Policy | Storage Media Policy |
| Process | Procedure for approving, using and disposing of removable media |
| Technical Control | USB restriction, encryption, endpoint control |
| Record | Media register |
| Evidence | Disposal certificate |
| Review | Periodic storage media control review |
An auditor is generally interested in whether the organization has implemented effective controls, not simply whether a policy exists.
Relationship With Other ISO 27001 Controls
Annex A 7.10 works closely with several other controls.
| Control | Relationship |
|---|---|
| A.5.9 Inventory of Information and Other Associated Assets | Helps identify devices and storage assets |
| A.5.10 Acceptable Use | Defines acceptable use of storage media |
| A.5.11 Return of Assets | Covers return of storage devices/assets |
| A.5.12 Classification of Information | Determines protection based on information sensitivity |
| A.5.13 Labelling of Information | Helps identify information requiring protection |
| A.5.14 Information Transfer | Relevant when information is transferred using media |
| A.5.15 Access Control | Restricts access to information |
| A.5.18 Access Rights | Controls authorization |
| A.5.33 Protection of Records | Relevant to records stored on media |
| A.5.34 Privacy and Protection of PII | Important when media contains personal information |
| A.6.3 Awareness, Education and Training | Employees need to understand media risks |
| A.6.5 Responsibilities After Termination | Relevant when devices/media are returned |
| A.6.7 Remote Working | Relevant when storage media is used outside the office |
| A.7.5 Physical and Environmental Threats | Protects physical media from environmental risks |
| A.7.8 Equipment Siting and Protection | Protects equipment containing storage |
| A.7.9 Security of Assets Off-Premises | Protects storage devices outside organizational premises |
| A.8.1 User Endpoint Devices | Protects laptops, desktops and similar devices |
| A.8.10 Information Deletion | Relevant to secure deletion |
| A.8.13 Information Backup | Important for backup media |
| A.8.15 Logging | May provide evidence of relevant activity |
A.7.9 vs A.7.10
These controls are closely related but have different focuses.
| Control | Main Focus |
|---|---|
| A.7.9 Security of Assets Off-Premises | Protecting assets when they are outside organizational premises |
| A.7.10 Storage Media | Managing and protecting media that stores information throughout its lifecycle |
Example
An employee takes an encrypted company laptop home.
- A.7.9 → protects the laptop and information while it is off-premises.
- A.7.10 → addresses how the storage media containing information is managed and protected.
A.7.10 vs A.8.10 Information Deletion
These controls also complement each other.
A.7.10 focuses on managing storage media.
A.8.10 focuses on ensuring information is deleted when it is no longer required.
For example:
Old SSD → determine information sensitivity → securely erase information → verify appropriate sanitization → retire/dispose of SSD.
This combines media management with information deletion.
Useful Resources
Organizations can create practical supporting documents for Annex A 7.10.
Recommended documents
- Storage Media Policy
[Insert Draft Document Link] - Removable Media Procedure
[Insert Draft Document Link] - Storage Media Register
[Insert Draft Document Link] - Storage Media Risk Assessment
[Insert Draft Document Link] - USB / Removable Media Authorization Form
[Insert Draft Document Link] - Storage Media Disposal Procedure
[Insert Draft Document Link] - Media Sanitization Record
[Insert Draft Document Link] - Media Destruction Certificate Template
[Insert Draft Document Link] - Backup Media Register
[Insert Draft Document Link] - Storage Media Audit Checklist
[Insert Draft Document Link]
Questions an Auditor May Ask
An auditor may ask:
1. What types of storage media does your organization use?
Be prepared to explain laptops, mobile devices, backup media, USB drives, external drives and other relevant media.
2. Can employees use personal USB devices?
Explain your policy and technical controls.
3. How do you protect sensitive information stored on removable media?
Explain encryption and access restrictions.
4. What happens when a storage device is lost?
Explain the incident-reporting and response process.
5. How do you dispose of old hard drives?
Show your secure disposal/sanitization process.
6. How do you handle backup media?
Explain storage, encryption, access, retention and disposal.
7. How do you prevent unauthorized copying?
Explain endpoint controls, permissions, DLP or other relevant measures.
8. How do you handle media containing personal information?
Explain classification, access, protection, retention and secure deletion.
9. How do you know storage media was securely destroyed?
Provide destruction or sanitization records where applicable.
10. How are employees trained?
Show awareness or training records covering acceptable use and information handling.
Startup-Focused Final Takeaway
ISO 27001 Annex A 7.10 is not about creating a complicated inventory of every hard drive in the organization.
It is about maintaining control over information stored on physical and removable media throughout its lifecycle.
A practical startup approach is:
Identify → Classify → Authorize → Protect → Transport → Store → Reuse Safely → Dispose Securely → Review
Before implementing this control, ask:
- What storage media do we actually use?
- What information can be stored on it?
- Which information is sensitive?
- Who is authorized to use it?
- Is sensitive data encrypted?
- What happens when media is lost?
- What happens when media is reused?
- What happens when media is no longer required?
- Can we demonstrate these controls to an auditor?
The simple rule
If information can be stored on it, the organization should have an appropriate way to protect it.
For startups, the goal is not to eliminate every storage medium.
The goal is to ensure that information does not lose its protection simply because it was moved from a cloud system to a laptop, USB drive, external disk, backup device, or other storage medium.
