What is ISO 27001 Annex A 7.14 – Secure Disposal or Re-use of Equipment?
ISO 27001 Annex A 7.14 focuses on ensuring that equipment containing storage media or information is securely disposed of or re-used so that sensitive information cannot be recovered by unauthorized people.
When a laptop, desktop, server, hard drive, mobile device, printer, USB drive, or other equipment is retired, sold, returned, donated, recycled, or reassigned, the organization must consider what information may still remain on it.
This control helps organizations:
- Prevent recovery of confidential information
- Protect customer and employee data
- Prevent exposure of credentials, keys, certificates, and configuration information
- Securely dispose of obsolete equipment
- Securely re-use equipment internally
- Reduce the risk of data leakage
- Maintain evidence of secure disposal
- Meet contractual, legal, regulatory, and customer requirements
Simple explanation: Before equipment leaves your control or is given to another user, make sure the information stored on it cannot be recovered by an unauthorized person.
Why is ISO 27001 Annex A 7.14 Important?
Deleting a file is not necessarily the same as securely removing the information.
For example, an employee’s laptop may contain:
- Customer information
- Downloaded reports
- Email caches
- Browser data
- Saved credentials
- VPN configuration
- SSH keys
- API tokens
- Source code
- Business documents
- Local database files
- Security investigation information
If the laptop is simply given to another employee or sold to a third party without appropriate sanitization, some of this information may remain recoverable.
Common risks
| Situation | Potential Risk |
|---|---|
| Old laptop sold | Previous company data may be recovered |
| Employee laptop reassigned | Previous user’s information remains accessible |
| Failed hard drive sent for repair | Sensitive information may be exposed |
| Old server recycled | Customer or business data may remain |
| USB drive discarded | Confidential files may be recovered |
| Printer replaced | Stored documents/configuration may remain |
| Mobile phone returned | Business email and application data may remain |
| Storage device sent to recycler | Data may be accessed by another party |
The risk is particularly significant when equipment contains sensitive, confidential, regulated, or customer information.
Simple principle: Do not dispose of the hardware until you have addressed the information stored on it.
What Does Annex A 7.14 Require?
The organization should establish appropriate processes to ensure that information stored on equipment is securely removed before disposal or re-use, according to the organization’s information classification, risk, and applicable requirements.
The process should consider:
- What information is stored on the equipment
- Sensitivity of the information
- Type of storage media
- Whether the equipment will be re-used internally
- Whether it will leave the organization
- Whether the equipment is being returned to a supplier
- Whether the equipment is being recycled or destroyed
- Whether secure erasure is technically possible
- Whether physical destruction is required
- Legal and contractual requirements
- Customer requirements
- Evidence that disposal or sanitization was completed
The organization should also consider equipment that fails or cannot be securely erased.
Secure Disposal vs Secure Re-use
These are related but slightly different situations.
| Situation | Objective |
|---|---|
| Re-use within organization | Remove previous user’s information before assigning equipment to another person |
| Re-use for another purpose | Remove old information before changing the equipment’s role |
| Return to supplier | Ensure company information is removed before return where applicable |
| Sale | Ensure information cannot be recovered by the buyer |
| Donation | Ensure information cannot be recovered by the recipient |
| Recycling | Ensure storage media does not expose information |
| Physical destruction | Destroy storage media when secure erasure is not sufficient or feasible |
What is Secure Data Sanitization?
Data sanitization is the process of making information on storage media inaccessible or practically unrecoverable using an appropriate method.
Depending on the situation, this may involve:
- Secure wiping
- Cryptographic erasure
- Manufacturer-supported secure erase functions
- Overwriting where appropriate
- Factory reset combined with appropriate organizational controls
- Physical destruction
- Certified destruction services
The appropriate method depends on the type of media, information sensitivity, technology, and risk.
For example, simply deleting a file or formatting a disk may not provide the level of assurance required for sensitive information.
Activities Required to Implement A.7.14
1. Identify Equipment That May Contain Information
Start with the organization’s asset inventory.
Identify equipment such as:
- Laptops
- Desktops
- Servers
- Hard drives
- SSDs
- Mobile phones
- Tablets
- USB drives
- External drives
- Backup media
- Printers
- Network equipment
- Security appliances
- Storage devices
- Specialized equipment
The inventory should ideally identify whether the asset contains storage media.
2. Identify the Information Stored on the Equipment
Consider the organization’s information classification.
For example:
| Equipment | Possible Information |
|---|---|
| Employee laptop | HR documents, email, business data |
| Developer laptop | Source code, credentials, API keys |
| Finance laptop | Financial information |
| Server | Application/customer data |
| Mobile phone | Email, applications, contacts |
| Printer | Printed-document cache |
| USB drive | Customer reports |
| Backup media | Large volumes of organizational data |
This helps determine the appropriate sanitization method.
3. Define Disposal and Re-use Rules
Create a documented procedure covering:
- When equipment can be retired
- Who can authorize disposal
- How information must be removed
- Who performs sanitization
- How disposal vendors are controlled
- What evidence must be retained
- How failed storage devices are handled
- How equipment is approved for re-use
4. Classify the Information Before Disposal
The more sensitive the information, the stronger the disposal controls may need to be.
Example:
| Information | Example | Disposal Consideration |
|---|---|---|
| Public | Published website content | Normal disposal process |
| Internal | Internal procedures | Standard sanitization |
| Confidential | Contracts, business records | Controlled sanitization |
| Restricted | Customer/employee sensitive data | Strong sanitization |
| Highly sensitive | Credentials, regulated data, critical secrets | Enhanced sanitization/destruction where appropriate |
5. Select an Appropriate Sanitization Method
The organization should select the method based on risk and technology.
Example decision process
Does the equipment contain sensitive information?
↓
Can the storage media be securely sanitized?
↓
Yes → Perform approved sanitization
↓
Verify completion
↓
Record evidence
↓
Release equipment for re-use/disposal
If secure sanitization cannot be reliably performed:
Consider physical destruction or an appropriately controlled specialist disposal service.
Example: Secure Re-use of a Laptop
Suppose a SaaS startup has an employee leaving the organization.
The employee’s laptop contains:
- Company email
- Customer documents
- Source code
- Browser data
- VPN configuration
- Local files
- Security certificates
The company should not simply give the laptop to the next employee.
Appropriate process
Employee leaves
↓
IT receives laptop
↓
Asset status updated
↓
Company data backed up where required
↓
Account access removed
↓
Storage sanitized using approved method
↓
Sanitization verified
↓
Device reconfigured
↓
Device security controls applied
↓
Laptop assigned to new employee
↓
Asset register updated
This provides both operational and audit evidence.
Startup Example
Imagine a 40-person SaaS startup using:
- Windows and Mac laptops
- Google Workspace
- GitHub
- AWS
- Slack
- Mobile devices
- A few USB drives
- External SSDs
Every year, several laptops are replaced.
A simple startup disposal process could be:
- Employee returns laptop
- IT checks the asset against the inventory
- Business information is retained or transferred if required
- Device is removed from the previous user’s management account
- Storage is securely sanitized
- Sanitization is verified
- Device is either re-issued or sent for disposal
- Disposal/re-use is recorded
- Third-party disposal certificates are retained where applicable
This is much better than simply deleting the employee’s files.
What If the Hard Drive Has Failed?
This is an important scenario.
Suppose a laptop has a failed SSD and cannot be booted.
The organization should not assume:
“The laptop doesn’t work, so the data is gone.”
The storage device may still contain recoverable information.
Depending on the sensitivity and technical circumstances, the organization may need to:
- Remove the storage media
- Use an appropriate specialist sanitization process
- Use physical destruction where appropriate
- Use a controlled disposal provider
- Obtain evidence/certification of destruction
Example
Failed laptop
→ Storage cannot be securely erased
→ Sensitive customer information may exist
→ Physical storage media is removed
→ Approved destruction process
→ Destruction evidence retained
→ Equipment disposed of
Secure Disposal of Mobile Devices
Mobile devices should also be included.
Examples:
- Company smartphones
- Tablets
- Corporate iPads
- Android devices
- Devices used for MFA
- Devices accessing customer applications
Before disposal or re-use, consider:
- Company account removal
- Mobile device management removal/reassignment
- Encryption
- Factory reset
- Removal of business applications
- Removal of authentication information
- SIM/eSIM handling
- Verification that organizational information is no longer accessible
Secure Disposal of Printers and Multifunction Devices
Printers are often overlooked.
Modern multifunction printers may contain:
- Internal storage
- Printed-document history
- Scanned documents
- Network configuration
- Email configuration
- Credentials
- Address books
- Authentication information
Therefore, when a printer is:
- Replaced
- Returned to a supplier
- Sold
- Leased back
- Disposed of
the organization should determine whether stored information must be securely removed.
Third-Party Disposal Providers
Many organizations use external vendors for electronic waste disposal.
This creates a supplier-security consideration.
The organization should evaluate:
- Vendor reputation
- Data destruction capability
- Chain of custody
- Secure transportation
- Destruction method
- Subcontractors
- Disposal records
- Certificates of destruction
- Contractual obligations
- Regulatory requirements
For highly sensitive equipment, the organization may require stronger evidence than a simple invoice stating that equipment was collected.
Example Equipment Disposal Register
| Asset ID | Equipment | Storage | Information Classification | Action | Method | Date | Performed By | Evidence |
|---|---|---|---|---|---|---|---|---|
| LAP-001 | Laptop | SSD | Confidential | Re-use | Secure sanitization | 10-Sep | IT Admin | Sanitization record |
| LAP-014 | Laptop | SSD | Restricted | Disposal | Secure erase | 12-Sep | IT Admin | Erasure record |
| HDD-006 | HDD | HDD | Restricted | Disposal | Physical destruction | 15-Sep | Vendor | Destruction certificate |
| MOB-022 | Mobile | Flash | Confidential | Re-use | Managed reset | 18-Sep | IT Admin | MDM record |
A simple register can provide significant audit evidence.
Equipment Disposal Decision Matrix
| Situation | Example | Possible Approach |
|---|---|---|
| Internal re-use | Laptop reassigned | Secure sanitization |
| External sale | Old laptop sold | Secure sanitization |
| Donation | Laptop donated | Secure sanitization |
| Supplier return | Leased device returned | Data removal + supplier confirmation |
| Failed storage | Damaged HDD | Destruction or specialist sanitization |
| Highly sensitive data | Restricted customer data | Enhanced sanitization/destruction |
| Recycling | E-waste | Controlled disposal + evidence |
The actual method should be determined according to the organization’s risk, technology, information sensitivity, and applicable requirements.
Disposal vs Re-use vs Return
These scenarios should be distinguished.
Re-use
The equipment remains under organizational control.
Example:
Employee A leaves → laptop sanitized → laptop assigned to Employee B.
Disposal
The equipment leaves the organization’s control permanently.
Example:
Old laptop → secure sanitization → authorized e-waste recycler.
Return
The equipment is returned to another party.
Example:
Leased laptop → organizational information securely removed → laptop returned to supplier.
The organization should consider information security in all three cases.
What Evidence Should an Auditor Expect?
An auditor may look for evidence that the organization does not simply discard equipment without considering information stored on it.
Possible evidence includes:
Policies and Procedures
- Information Security Policy
- Asset Management Policy
- Equipment Disposal Procedure
- Media Sanitization Procedure
- Secure Disposal Policy
- Acceptable Use Policy
Operational Records
- Asset register
- Equipment disposal register
- Equipment re-use records
- Data sanitization records
- Erasure logs
- Destruction certificates
- Vendor disposal records
- Chain-of-custody records
- Asset transfer forms
- Equipment return records
Technical Evidence
Where applicable:
- MDM records
- Endpoint management records
- Secure erase logs
- Device reset records
- Disk encryption records
- Storage sanitization reports
Audit Checklist for A.7.14
| Audit Question | Yes/No | Evidence |
|---|---|---|
| Does the organization have a secure disposal process? | ||
| Does the process cover re-use as well as disposal? | ||
| Are assets containing storage media identified? | ||
| Is information classification considered? | ||
| Are appropriate sanitization methods defined? | ||
| Are failed storage devices addressed? | ||
| Are third-party disposal vendors controlled? | ||
| Are disposal records maintained? | ||
| Are destruction certificates obtained where required? | ||
| Are returned devices securely handled? | ||
| Are mobile devices included? | ||
| Are printers and multifunction devices considered? | ||
| Is equipment re-use authorized? | ||
| Is sanitization verified before re-use? | ||
| Are disposal records linked to asset IDs? | ||
| Are legal/contractual requirements considered? | ||
| Are disposal practices periodically reviewed? |
Common Mistakes
1. Simply deleting files
Deleting files does not necessarily provide sufficient assurance that information cannot be recovered.
2. Formatting the hard drive and assuming it is secure
A basic format may not provide the required level of sanitization for sensitive information.
3. Forgetting failed equipment
A broken laptop or hard drive can still contain sensitive information.
4. Ignoring mobile phones
Mobile devices may contain email, authentication information, customer applications, photographs, documents, and other business information.
5. Ignoring printers
Printers and multifunction devices may contain internal storage.
6. No disposal evidence
An organization may securely dispose of equipment but have no records proving that it happened.
For an audit, the organization should be able to demonstrate the process.
7. No control over disposal vendors
Sending equipment to an unknown recycler without considering information security can create unnecessary risk.
8. Not updating the asset register
The organization may securely dispose of equipment but still show the asset as active.
The asset lifecycle should be updated.
9. Treating all equipment identically
A public information kiosk and a laptop containing sensitive customer data may require very different disposal controls.
Controls should be risk-based.
10. Forgetting equipment returned to suppliers
Leased or rented equipment may still contain organizational information when returned.
Practical Startup Implementation Model
A startup does not need an expensive disposal program.
A practical model is:
1. Identify
What equipment contains organizational information?
2. Classify
What type of information is stored on it?
3. Assess
What is the risk if information is recovered?
4. Authorize
Who can approve disposal or re-use?
5. Sanitize
Use an appropriate approved method.
6. Verify
Confirm that sanitization/destruction was completed.
7. Dispose or Re-use
Release the equipment only after security requirements are satisfied.
8. Record
Update the asset register and retain evidence.
9. Review
Periodically review whether the process remains effective.
Simple startup formula:
Identify → Classify → Assess → Sanitize → Verify → Dispose/Re-use → Record
Policy vs. Process vs. Evidence
A common ISO 27001 mistake is creating a disposal policy without demonstrating that the organization actually follows it.
| Layer | Example |
|---|---|
| Policy | Equipment must be securely disposed of or sanitized before re-use |
| Process | IT follows an approved sanitization workflow |
| Record | Laptop LAP-014 was securely sanitized |
| Evidence | Sanitization log/certificate |
| Asset Register | LAP-014 status changed to disposed/re-issued |
The strongest implementation connects all five.
Relationship With Other ISO 27001 Controls
A.7.14 works together with several other controls.
| Control | Relationship |
|---|---|
| A.5.9 Inventory of information and other associated assets | Identifies equipment that needs lifecycle management |
| A.5.10 Acceptable use | Defines appropriate use of organizational equipment |
| A.5.11 Return of assets | Ensures equipment is returned when employment/engagement ends |
| A.5.12 Classification of information | Helps determine appropriate disposal protection |
| A.5.13 Labelling of information | Supports identification and handling |
| A.5.33 Protection of records | Helps determine what records must be retained |
| A.6.5 Responsibilities after termination | Supports secure return and removal of employee access |
| A.7.8 Equipment siting and protection | Protects equipment while it is in use |
| A.7.9 Security of assets off-premises | Protects equipment outside organizational premises |
| A.7.10 Storage media | Addresses protection of storage media throughout its lifecycle |
| A.7.13 Equipment maintenance | Addresses equipment maintenance before retirement/replacement |
| A.8.10 Information deletion | Addresses deletion of information from systems and storage |
| A.8.12 Data leakage prevention | Helps prevent unauthorized information disclosure |
A.7.10 vs A.7.14
These controls are closely related but should not be treated as identical.
| A.7.10 | A.7.14 |
|---|---|
| Storage media | Equipment disposal/re-use |
| Focuses on media throughout its lifecycle | Focuses on equipment being disposed of or re-used |
| Covers handling, transport, storage, disposal | Specifically addresses secure disposal/re-use |
| Example: USB handling | Example: laptop retirement |
Simple distinction
A.7.10: How do we protect storage media?
A.7.14: What do we do when equipment containing information is going to be re-used or disposed of?
A.7.14 vs A.8.10 Information Deletion
These controls also complement each other.
A.8.10 – Information Deletion
Focuses on deleting information when it is no longer required.
A.7.14 – Secure Disposal or Re-use
Focuses on what happens to equipment containing information when that equipment is re-used or disposed of.
Example
A company deletes unnecessary customer files from an active laptop.
→ A.8.10
The laptop is later retired and given to another employee.
→ A.7.14
Both controls may therefore apply during the equipment lifecycle.
Useful Resources for A.7.14
Organizations can create the following documents:
1. Equipment Disposal and Re-use Policy
[Insert Draft Document Link]
Defines organizational requirements for secure disposal and re-use.
2. Equipment Disposal Procedure
[Insert Draft Document Link]
Defines the operational workflow.
3. Media Sanitization Procedure
[Insert Draft Document Link]
Defines approved sanitization methods.
4. Equipment Disposal Register
[Insert Draft Document Link]
Records equipment that has been disposed of or re-used.
5. Data Destruction Certificate Template
[Insert Draft Document Link]
Used to document secure destruction.
6. Equipment Re-use Checklist
[Insert Draft Document Link]
Used before equipment is reassigned.
7. IT Asset Return Form
[Insert Draft Document Link]
Documents return of equipment by employees or contractors.
8. Third-Party E-Waste Disposal Checklist
[Insert Draft Document Link]
Used to assess and monitor disposal providers.
Questions an Auditor May Ask
An auditor may ask:
- How do you securely dispose of old laptops?
- What happens when an employee leaves with a company laptop?
- How do you sanitize a laptop before re-use?
- What happens when a hard drive fails?
- How do you handle old mobile phones?
- Do your printers contain storage?
- How do you control third-party disposal vendors?
- Can you show an example of a recent disposal?
- Can you show evidence that the information was securely removed?
- How do you update your asset register?
- Who is authorized to approve disposal?
- What happens if secure erasure is technically impossible?
- How do you handle leased equipment?
- How do you determine the appropriate disposal method?
- How do you handle equipment containing sensitive or regulated information?
A good audit response should be supported by actual records, not only a policy.
Startup-Focused Quick Summary
For a small startup, A.7.14 can be implemented without creating a complicated process.
Minimum practical controls
- Maintain an equipment/asset register
- Identify equipment containing storage media
- Define an equipment disposal/re-use procedure
- Consider information sensitivity
- Use an approved sanitization method
- Securely handle failed storage devices
- Control third-party disposal vendors
- Obtain destruction evidence where appropriate
- Record every disposal/re-use event
- Update the asset register
- Periodically review the process
Example startup workflow
Employee leaves
→ Equipment returned
→ IT checks asset
→ Data retained/transferred where required
→ Access removed
→ Device sanitized
→ Sanitization verified
→ Device re-used or disposed
→ Evidence recorded
→ Asset register updated
Startup-Focused Final Takeaway
ISO 27001 Annex A 7.14 is not simply about throwing away old computers securely.
It is about managing the last stage of the information lifecycle.
A company should know:
- What equipment is being retired
- What information may be stored on it
- How sensitive that information is
- Whether the equipment will be re-used, returned, sold, donated, or destroyed
- What sanitization method is appropriate
- Who performed the activity
- What evidence proves it was completed
For startups, the process can remain simple.
Know the asset → understand the information → choose the right sanitization method → verify → dispose or re-use → keep evidence.
The key audit question is:
“Can you demonstrate that information stored on retired or re-used equipment cannot be accessed by an unauthorized person?”
If the answer is supported by a documented process, appropriate technical controls, actual disposal/re-use records, and evidence, the organization has a much stronger implementation of ISO 27001 Annex A 7.14.
One-Line Summary
ISO 27001 Annex A 7.14 ensures that equipment is securely sanitized before it is re-used, returned, recycled, sold, donated, or disposed of, preventing unauthorized recovery of organizational information.
