ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.14 Secure disposal or re-use of equipment

ISO 27001 Annex A 7.14 Secure disposal or re-use of equipment

What is ISO 27001 Annex A 7.14 – Secure Disposal or Re-use of Equipment?

ISO 27001 Annex A 7.14 focuses on ensuring that equipment containing storage media or information is securely disposed of or re-used so that sensitive information cannot be recovered by unauthorized people.

When a laptop, desktop, server, hard drive, mobile device, printer, USB drive, or other equipment is retired, sold, returned, donated, recycled, or reassigned, the organization must consider what information may still remain on it.

This control helps organizations:

  • Prevent recovery of confidential information
  • Protect customer and employee data
  • Prevent exposure of credentials, keys, certificates, and configuration information
  • Securely dispose of obsolete equipment
  • Securely re-use equipment internally
  • Reduce the risk of data leakage
  • Maintain evidence of secure disposal
  • Meet contractual, legal, regulatory, and customer requirements

Simple explanation: Before equipment leaves your control or is given to another user, make sure the information stored on it cannot be recovered by an unauthorized person.


Why is ISO 27001 Annex A 7.14 Important?

Deleting a file is not necessarily the same as securely removing the information.

For example, an employee’s laptop may contain:

  • Customer information
  • Downloaded reports
  • Email caches
  • Browser data
  • Saved credentials
  • VPN configuration
  • SSH keys
  • API tokens
  • Source code
  • Business documents
  • Local database files
  • Security investigation information

If the laptop is simply given to another employee or sold to a third party without appropriate sanitization, some of this information may remain recoverable.

Common risks

SituationPotential Risk
Old laptop soldPrevious company data may be recovered
Employee laptop reassignedPrevious user’s information remains accessible
Failed hard drive sent for repairSensitive information may be exposed
Old server recycledCustomer or business data may remain
USB drive discardedConfidential files may be recovered
Printer replacedStored documents/configuration may remain
Mobile phone returnedBusiness email and application data may remain
Storage device sent to recyclerData may be accessed by another party

The risk is particularly significant when equipment contains sensitive, confidential, regulated, or customer information.

Simple principle: Do not dispose of the hardware until you have addressed the information stored on it.


What Does Annex A 7.14 Require?

The organization should establish appropriate processes to ensure that information stored on equipment is securely removed before disposal or re-use, according to the organization’s information classification, risk, and applicable requirements.

The process should consider:

  • What information is stored on the equipment
  • Sensitivity of the information
  • Type of storage media
  • Whether the equipment will be re-used internally
  • Whether it will leave the organization
  • Whether the equipment is being returned to a supplier
  • Whether the equipment is being recycled or destroyed
  • Whether secure erasure is technically possible
  • Whether physical destruction is required
  • Legal and contractual requirements
  • Customer requirements
  • Evidence that disposal or sanitization was completed

The organization should also consider equipment that fails or cannot be securely erased.


Secure Disposal vs Secure Re-use

These are related but slightly different situations.

SituationObjective
Re-use within organizationRemove previous user’s information before assigning equipment to another person
Re-use for another purposeRemove old information before changing the equipment’s role
Return to supplierEnsure company information is removed before return where applicable
SaleEnsure information cannot be recovered by the buyer
DonationEnsure information cannot be recovered by the recipient
RecyclingEnsure storage media does not expose information
Physical destructionDestroy storage media when secure erasure is not sufficient or feasible

What is Secure Data Sanitization?

Data sanitization is the process of making information on storage media inaccessible or practically unrecoverable using an appropriate method.

Depending on the situation, this may involve:

  • Secure wiping
  • Cryptographic erasure
  • Manufacturer-supported secure erase functions
  • Overwriting where appropriate
  • Factory reset combined with appropriate organizational controls
  • Physical destruction
  • Certified destruction services

The appropriate method depends on the type of media, information sensitivity, technology, and risk.

For example, simply deleting a file or formatting a disk may not provide the level of assurance required for sensitive information.


Activities Required to Implement A.7.14

1. Identify Equipment That May Contain Information

Start with the organization’s asset inventory.

Identify equipment such as:

  • Laptops
  • Desktops
  • Servers
  • Hard drives
  • SSDs
  • Mobile phones
  • Tablets
  • USB drives
  • External drives
  • Backup media
  • Printers
  • Network equipment
  • Security appliances
  • Storage devices
  • Specialized equipment

The inventory should ideally identify whether the asset contains storage media.


2. Identify the Information Stored on the Equipment

Consider the organization’s information classification.

For example:

EquipmentPossible Information
Employee laptopHR documents, email, business data
Developer laptopSource code, credentials, API keys
Finance laptopFinancial information
ServerApplication/customer data
Mobile phoneEmail, applications, contacts
PrinterPrinted-document cache
USB driveCustomer reports
Backup mediaLarge volumes of organizational data

This helps determine the appropriate sanitization method.


3. Define Disposal and Re-use Rules

Create a documented procedure covering:

  • When equipment can be retired
  • Who can authorize disposal
  • How information must be removed
  • Who performs sanitization
  • How disposal vendors are controlled
  • What evidence must be retained
  • How failed storage devices are handled
  • How equipment is approved for re-use

4. Classify the Information Before Disposal

The more sensitive the information, the stronger the disposal controls may need to be.

Example:

InformationExampleDisposal Consideration
PublicPublished website contentNormal disposal process
InternalInternal proceduresStandard sanitization
ConfidentialContracts, business recordsControlled sanitization
RestrictedCustomer/employee sensitive dataStrong sanitization
Highly sensitiveCredentials, regulated data, critical secretsEnhanced sanitization/destruction where appropriate

5. Select an Appropriate Sanitization Method

The organization should select the method based on risk and technology.

Example decision process

Does the equipment contain sensitive information?

↓

Can the storage media be securely sanitized?

↓

Yes → Perform approved sanitization

↓

Verify completion

↓

Record evidence

↓

Release equipment for re-use/disposal

If secure sanitization cannot be reliably performed:

Consider physical destruction or an appropriately controlled specialist disposal service.


Example: Secure Re-use of a Laptop

Suppose a SaaS startup has an employee leaving the organization.

The employee’s laptop contains:

  • Company email
  • Customer documents
  • Source code
  • Browser data
  • VPN configuration
  • Local files
  • Security certificates

The company should not simply give the laptop to the next employee.

Appropriate process

Employee leaves

↓

IT receives laptop

↓

Asset status updated

↓

Company data backed up where required

↓

Account access removed

↓

Storage sanitized using approved method

↓

Sanitization verified

↓

Device reconfigured

↓

Device security controls applied

↓

Laptop assigned to new employee

↓

Asset register updated

This provides both operational and audit evidence.


Startup Example

Imagine a 40-person SaaS startup using:

  • Windows and Mac laptops
  • Google Workspace
  • GitHub
  • AWS
  • Slack
  • Mobile devices
  • A few USB drives
  • External SSDs

Every year, several laptops are replaced.

A simple startup disposal process could be:

  1. Employee returns laptop
  2. IT checks the asset against the inventory
  3. Business information is retained or transferred if required
  4. Device is removed from the previous user’s management account
  5. Storage is securely sanitized
  6. Sanitization is verified
  7. Device is either re-issued or sent for disposal
  8. Disposal/re-use is recorded
  9. Third-party disposal certificates are retained where applicable

This is much better than simply deleting the employee’s files.


What If the Hard Drive Has Failed?

This is an important scenario.

Suppose a laptop has a failed SSD and cannot be booted.

The organization should not assume:

“The laptop doesn’t work, so the data is gone.”

The storage device may still contain recoverable information.

Depending on the sensitivity and technical circumstances, the organization may need to:

  • Remove the storage media
  • Use an appropriate specialist sanitization process
  • Use physical destruction where appropriate
  • Use a controlled disposal provider
  • Obtain evidence/certification of destruction

Example

Failed laptop

→ Storage cannot be securely erased

→ Sensitive customer information may exist

→ Physical storage media is removed

→ Approved destruction process

→ Destruction evidence retained

→ Equipment disposed of


Secure Disposal of Mobile Devices

Mobile devices should also be included.

Examples:

  • Company smartphones
  • Tablets
  • Corporate iPads
  • Android devices
  • Devices used for MFA
  • Devices accessing customer applications

Before disposal or re-use, consider:

  • Company account removal
  • Mobile device management removal/reassignment
  • Encryption
  • Factory reset
  • Removal of business applications
  • Removal of authentication information
  • SIM/eSIM handling
  • Verification that organizational information is no longer accessible

Secure Disposal of Printers and Multifunction Devices

Printers are often overlooked.

Modern multifunction printers may contain:

  • Internal storage
  • Printed-document history
  • Scanned documents
  • Network configuration
  • Email configuration
  • Credentials
  • Address books
  • Authentication information

Therefore, when a printer is:

  • Replaced
  • Returned to a supplier
  • Sold
  • Leased back
  • Disposed of

the organization should determine whether stored information must be securely removed.


Third-Party Disposal Providers

Many organizations use external vendors for electronic waste disposal.

This creates a supplier-security consideration.

The organization should evaluate:

  • Vendor reputation
  • Data destruction capability
  • Chain of custody
  • Secure transportation
  • Destruction method
  • Subcontractors
  • Disposal records
  • Certificates of destruction
  • Contractual obligations
  • Regulatory requirements

For highly sensitive equipment, the organization may require stronger evidence than a simple invoice stating that equipment was collected.


Example Equipment Disposal Register

Asset IDEquipmentStorageInformation ClassificationActionMethodDatePerformed ByEvidence
LAP-001LaptopSSDConfidentialRe-useSecure sanitization10-SepIT AdminSanitization record
LAP-014LaptopSSDRestrictedDisposalSecure erase12-SepIT AdminErasure record
HDD-006HDDHDDRestrictedDisposalPhysical destruction15-SepVendorDestruction certificate
MOB-022MobileFlashConfidentialRe-useManaged reset18-SepIT AdminMDM record

A simple register can provide significant audit evidence.


Equipment Disposal Decision Matrix

SituationExamplePossible Approach
Internal re-useLaptop reassignedSecure sanitization
External saleOld laptop soldSecure sanitization
DonationLaptop donatedSecure sanitization
Supplier returnLeased device returnedData removal + supplier confirmation
Failed storageDamaged HDDDestruction or specialist sanitization
Highly sensitive dataRestricted customer dataEnhanced sanitization/destruction
RecyclingE-wasteControlled disposal + evidence

The actual method should be determined according to the organization’s risk, technology, information sensitivity, and applicable requirements.


Disposal vs Re-use vs Return

These scenarios should be distinguished.

Re-use

The equipment remains under organizational control.

Example:

Employee A leaves → laptop sanitized → laptop assigned to Employee B.

Disposal

The equipment leaves the organization’s control permanently.

Example:

Old laptop → secure sanitization → authorized e-waste recycler.

Return

The equipment is returned to another party.

Example:

Leased laptop → organizational information securely removed → laptop returned to supplier.

The organization should consider information security in all three cases.


What Evidence Should an Auditor Expect?

An auditor may look for evidence that the organization does not simply discard equipment without considering information stored on it.

Possible evidence includes:

Policies and Procedures

  • Information Security Policy
  • Asset Management Policy
  • Equipment Disposal Procedure
  • Media Sanitization Procedure
  • Secure Disposal Policy
  • Acceptable Use Policy

Operational Records

  • Asset register
  • Equipment disposal register
  • Equipment re-use records
  • Data sanitization records
  • Erasure logs
  • Destruction certificates
  • Vendor disposal records
  • Chain-of-custody records
  • Asset transfer forms
  • Equipment return records

Technical Evidence

Where applicable:

  • MDM records
  • Endpoint management records
  • Secure erase logs
  • Device reset records
  • Disk encryption records
  • Storage sanitization reports

Audit Checklist for A.7.14

Audit QuestionYes/NoEvidence
Does the organization have a secure disposal process?
Does the process cover re-use as well as disposal?
Are assets containing storage media identified?
Is information classification considered?
Are appropriate sanitization methods defined?
Are failed storage devices addressed?
Are third-party disposal vendors controlled?
Are disposal records maintained?
Are destruction certificates obtained where required?
Are returned devices securely handled?
Are mobile devices included?
Are printers and multifunction devices considered?
Is equipment re-use authorized?
Is sanitization verified before re-use?
Are disposal records linked to asset IDs?
Are legal/contractual requirements considered?
Are disposal practices periodically reviewed?

Common Mistakes

1. Simply deleting files

Deleting files does not necessarily provide sufficient assurance that information cannot be recovered.


2. Formatting the hard drive and assuming it is secure

A basic format may not provide the required level of sanitization for sensitive information.


3. Forgetting failed equipment

A broken laptop or hard drive can still contain sensitive information.


4. Ignoring mobile phones

Mobile devices may contain email, authentication information, customer applications, photographs, documents, and other business information.


5. Ignoring printers

Printers and multifunction devices may contain internal storage.


6. No disposal evidence

An organization may securely dispose of equipment but have no records proving that it happened.

For an audit, the organization should be able to demonstrate the process.


7. No control over disposal vendors

Sending equipment to an unknown recycler without considering information security can create unnecessary risk.


8. Not updating the asset register

The organization may securely dispose of equipment but still show the asset as active.

The asset lifecycle should be updated.


9. Treating all equipment identically

A public information kiosk and a laptop containing sensitive customer data may require very different disposal controls.

Controls should be risk-based.


10. Forgetting equipment returned to suppliers

Leased or rented equipment may still contain organizational information when returned.


Practical Startup Implementation Model

A startup does not need an expensive disposal program.

A practical model is:

1. Identify

What equipment contains organizational information?

2. Classify

What type of information is stored on it?

3. Assess

What is the risk if information is recovered?

4. Authorize

Who can approve disposal or re-use?

5. Sanitize

Use an appropriate approved method.

6. Verify

Confirm that sanitization/destruction was completed.

7. Dispose or Re-use

Release the equipment only after security requirements are satisfied.

8. Record

Update the asset register and retain evidence.

9. Review

Periodically review whether the process remains effective.

Simple startup formula:
Identify → Classify → Assess → Sanitize → Verify → Dispose/Re-use → Record


Policy vs. Process vs. Evidence

A common ISO 27001 mistake is creating a disposal policy without demonstrating that the organization actually follows it.

LayerExample
PolicyEquipment must be securely disposed of or sanitized before re-use
ProcessIT follows an approved sanitization workflow
RecordLaptop LAP-014 was securely sanitized
EvidenceSanitization log/certificate
Asset RegisterLAP-014 status changed to disposed/re-issued

The strongest implementation connects all five.


Relationship With Other ISO 27001 Controls

A.7.14 works together with several other controls.

ControlRelationship
A.5.9 Inventory of information and other associated assetsIdentifies equipment that needs lifecycle management
A.5.10 Acceptable useDefines appropriate use of organizational equipment
A.5.11 Return of assetsEnsures equipment is returned when employment/engagement ends
A.5.12 Classification of informationHelps determine appropriate disposal protection
A.5.13 Labelling of informationSupports identification and handling
A.5.33 Protection of recordsHelps determine what records must be retained
A.6.5 Responsibilities after terminationSupports secure return and removal of employee access
A.7.8 Equipment siting and protectionProtects equipment while it is in use
A.7.9 Security of assets off-premisesProtects equipment outside organizational premises
A.7.10 Storage mediaAddresses protection of storage media throughout its lifecycle
A.7.13 Equipment maintenanceAddresses equipment maintenance before retirement/replacement
A.8.10 Information deletionAddresses deletion of information from systems and storage
A.8.12 Data leakage preventionHelps prevent unauthorized information disclosure

A.7.10 vs A.7.14

These controls are closely related but should not be treated as identical.

A.7.10A.7.14
Storage mediaEquipment disposal/re-use
Focuses on media throughout its lifecycleFocuses on equipment being disposed of or re-used
Covers handling, transport, storage, disposalSpecifically addresses secure disposal/re-use
Example: USB handlingExample: laptop retirement

Simple distinction

A.7.10: How do we protect storage media?

A.7.14: What do we do when equipment containing information is going to be re-used or disposed of?


A.7.14 vs A.8.10 Information Deletion

These controls also complement each other.

A.8.10 – Information Deletion

Focuses on deleting information when it is no longer required.

A.7.14 – Secure Disposal or Re-use

Focuses on what happens to equipment containing information when that equipment is re-used or disposed of.

Example

A company deletes unnecessary customer files from an active laptop.

→ A.8.10

The laptop is later retired and given to another employee.

→ A.7.14

Both controls may therefore apply during the equipment lifecycle.


Useful Resources for A.7.14

Organizations can create the following documents:

1. Equipment Disposal and Re-use Policy

[Insert Draft Document Link]

Defines organizational requirements for secure disposal and re-use.

2. Equipment Disposal Procedure

[Insert Draft Document Link]

Defines the operational workflow.

3. Media Sanitization Procedure

[Insert Draft Document Link]

Defines approved sanitization methods.

4. Equipment Disposal Register

[Insert Draft Document Link]

Records equipment that has been disposed of or re-used.

5. Data Destruction Certificate Template

[Insert Draft Document Link]

Used to document secure destruction.

6. Equipment Re-use Checklist

[Insert Draft Document Link]

Used before equipment is reassigned.

7. IT Asset Return Form

[Insert Draft Document Link]

Documents return of equipment by employees or contractors.

8. Third-Party E-Waste Disposal Checklist

[Insert Draft Document Link]

Used to assess and monitor disposal providers.


Questions an Auditor May Ask

An auditor may ask:

  1. How do you securely dispose of old laptops?
  2. What happens when an employee leaves with a company laptop?
  3. How do you sanitize a laptop before re-use?
  4. What happens when a hard drive fails?
  5. How do you handle old mobile phones?
  6. Do your printers contain storage?
  7. How do you control third-party disposal vendors?
  8. Can you show an example of a recent disposal?
  9. Can you show evidence that the information was securely removed?
  10. How do you update your asset register?
  11. Who is authorized to approve disposal?
  12. What happens if secure erasure is technically impossible?
  13. How do you handle leased equipment?
  14. How do you determine the appropriate disposal method?
  15. How do you handle equipment containing sensitive or regulated information?

A good audit response should be supported by actual records, not only a policy.


Startup-Focused Quick Summary

For a small startup, A.7.14 can be implemented without creating a complicated process.

Minimum practical controls

  • Maintain an equipment/asset register
  • Identify equipment containing storage media
  • Define an equipment disposal/re-use procedure
  • Consider information sensitivity
  • Use an approved sanitization method
  • Securely handle failed storage devices
  • Control third-party disposal vendors
  • Obtain destruction evidence where appropriate
  • Record every disposal/re-use event
  • Update the asset register
  • Periodically review the process

Example startup workflow

Employee leaves

→ Equipment returned

→ IT checks asset

→ Data retained/transferred where required

→ Access removed

→ Device sanitized

→ Sanitization verified

→ Device re-used or disposed

→ Evidence recorded

→ Asset register updated


Startup-Focused Final Takeaway

ISO 27001 Annex A 7.14 is not simply about throwing away old computers securely.

It is about managing the last stage of the information lifecycle.

A company should know:

  • What equipment is being retired
  • What information may be stored on it
  • How sensitive that information is
  • Whether the equipment will be re-used, returned, sold, donated, or destroyed
  • What sanitization method is appropriate
  • Who performed the activity
  • What evidence proves it was completed

For startups, the process can remain simple.

Know the asset → understand the information → choose the right sanitization method → verify → dispose or re-use → keep evidence.

The key audit question is:

“Can you demonstrate that information stored on retired or re-used equipment cannot be accessed by an unauthorized person?”

If the answer is supported by a documented process, appropriate technical controls, actual disposal/re-use records, and evidence, the organization has a much stronger implementation of ISO 27001 Annex A 7.14.


One-Line Summary

ISO 27001 Annex A 7.14 ensures that equipment is securely sanitized before it is re-used, returned, recycled, sold, donated, or disposed of, preventing unauthorized recovery of organizational information.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *