ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 4. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 7.10 Storage media

ISO 27001 Annex A 7.10 Storage media

What is ISO 27001 Annex A 7.10 – Storage Media?

ISO 27001 Annex A 7.10 – Storage Media requires organizations to manage storage media throughout its lifecycle so that information stored on the media is protected from unauthorized access, modification, loss, damage, or disclosure.

Storage media includes physical and removable devices that can store organizational information.

Examples include:

  • USB flash drives
  • External hard drives
  • SSDs
  • CDs/DVDs
  • Backup tapes
  • Memory cards
  • Mobile device storage
  • Laptop and desktop hard drives
  • Server drives
  • Backup media
  • Removable storage devices
  • Printed or physical media where applicable
  • Other portable or removable information storage

The organization should consider how storage media is:

Received → Classified → Used → Stored → Transported → Protected → Reused → Disposed

Simple explanation: If information can be stored on a device, the organization should know how that storage media is protected, handled, transported, reused, and securely disposed of.


Why is Annex A 7.10 Important?

Storage media can contain highly sensitive information.

For example, a single USB drive could contain:

  • Customer information
  • Employee records
  • Source code
  • Database exports
  • Security reports
  • Backup data
  • Financial information
  • Contracts
  • Credentials or configuration files
  • Personal information
  • Confidential business information

If the media is lost, stolen, copied, improperly reused, or disposed of without proper protection, sensitive information may be exposed.

Common risks

RiskExample
LossEmployee loses a USB containing customer data
TheftLaptop containing an unencrypted drive is stolen
Unauthorized accessExternal drive is connected to an unauthorized computer
Data leakageDatabase export is copied to removable media
Improper disposalOld hard drive is thrown away without secure erasure
Unauthorized copyingEmployee copies confidential files to a personal USB
MalwareInfected USB introduces malware into company systems
Uncontrolled backupBackup drive is stored without adequate protection
Physical damageStorage media is damaged by fire, water, or heat
Unauthorized reuseOld drive is reassigned without removing previous data

Simple principle: Protect the information, not just the storage device.


What Does ISO 27001 Annex A 7.10 Require?

The organization should establish appropriate controls for storage media based on:

  • Information classification
  • Business requirements
  • Security risks
  • Type of media
  • Sensitivity of information
  • Where the media is stored
  • Who can access it
  • Whether it is transported
  • Whether it is reused
  • Whether it needs to be destroyed
  • Legal, regulatory, and contractual requirements

ISO 27001 does not mean that every organization must ban USB drives.

Instead, the organization should determine:

What storage media do we use?

What information can be stored on it?

Who can use it?

How is it protected?

What happens when it is no longer required?


What is Storage Media?

Storage media is any physical or electronic medium capable of storing information.

Common examples

Storage MediaExample Use
USB driveTemporary file transfer
External HDD/SSDBackup or data transfer
Laptop SSDOperating system and business data
Server diskApplication/database storage
Backup tapeLong-term backup
SD cardCameras or specialized equipment
Mobile storagePhones/tablets
CD/DVDLegacy archives
Removable backup mediaOffline backups
Encrypted portable driveSecure transfer of sensitive data

For a modern SaaS startup, much of the production data may be stored in cloud platforms rather than removable physical media.

However, storage media can still exist through:

  • Employee laptops
  • Backup systems
  • External drives
  • Mobile devices
  • Developer machines
  • Security tools
  • Database exports
  • Offline backups
  • USB devices

Storage Media Lifecycle

A practical approach is to manage storage media through its entire lifecycle:

Acquire → Register → Classify → Authorize → Use → Store → Transport → Monitor → Reuse → Dispose

The organization should determine the appropriate controls at each stage.


Activities Required to Implement Annex A 7.10

1. Identify Storage Media

First, identify what types of storage media are used within the organization.

For example:

  • Company laptops
  • External hard drives
  • USB drives
  • Backup drives
  • Mobile devices
  • Server storage
  • Offline backups
  • Removable media used by IT teams

Do not limit the assessment to devices owned by the IT department.

Consider how employees, contractors, developers, administrators, and third parties use storage media.


2. Identify What Information is Stored

Determine what types of information can be stored on each medium.

For example:

Storage MediaInformation
Employee laptopBusiness documents, email, source code
Backup driveDatabase backup
USB driveTemporary file transfer
Mobile phoneEmail, messages, business applications
External SSDSecurity assessment reports
Server diskApplication/database information

This should be connected to Annex A 5.12 – Classification of Information.


3. Define Acceptable Use

Establish clear rules for the use of removable and portable storage.

For example:

  • Only company-approved USB devices may be used.
  • Personal USB devices should not be used for company information.
  • Sensitive information should not be copied to removable media unless authorized.
  • Storage devices containing confidential information should be encrypted.
  • Unknown USB devices should not be connected to company systems.
  • Lost or stolen storage media must be reported immediately.

4. Control Removable Media

Organizations can implement controls such as:

  • USB device restrictions
  • Endpoint security policies
  • Device control software
  • Encryption
  • Access permissions
  • Malware scanning
  • Administrator approval
  • Data Loss Prevention controls
  • Logging where appropriate

The appropriate level depends on the organization’s risk.

A 10-person startup does not necessarily need an expensive enterprise DLP platform simply because ISO 27001 requires storage media controls.

A documented policy combined with endpoint configuration, encryption, employee awareness, and access controls may be appropriate.


5. Protect Sensitive Information on Storage Media

Where sensitive information is stored on portable media, appropriate protection should be applied.

Examples include:

  • Full-disk encryption
  • Encrypted USB drives
  • File-level encryption
  • Password protection where appropriate
  • Access controls
  • Strong authentication
  • Secure storage
  • Controlled transportation

For example:

Customer database export → encrypted external drive → authorized employee → controlled transfer → secure deletion after use.


6. Control Transportation of Storage Media

Storage media may be physically transported between:

  • Offices
  • Data centers
  • Backup locations
  • Customer sites
  • Employees
  • Suppliers
  • Disaster recovery locations

Transportation risks should be considered.

Controls may include:

  • Encryption
  • Tamper-evident packaging
  • Authorized couriers
  • Chain-of-custody records
  • Secure containers
  • Delivery confirmation
  • Restricted access

7. Protect Storage Media From Physical Damage

Storage media should be protected from:

  • Fire
  • Water
  • Excessive heat
  • Humidity
  • Dust
  • Physical impact
  • Magnetic or electrical risks where relevant
  • Theft
  • Unauthorized handling

This connects with:

  • A.7.5 – Protecting Against Physical and Environmental Threats
  • A.7.8 – Equipment Siting and Protection
  • A.8.13 – Information Backup

8. Manage Backup Media

If physical media is used for backups, the organization should consider:

  • Backup classification
  • Encryption
  • Access restrictions
  • Storage location
  • Retention period
  • Backup frequency
  • Transportation
  • Restoration testing
  • Physical protection
  • Secure destruction

For example:

Production database → encrypted backup → protected backup location → periodic restore test → retention period → secure disposal


9. Manage Reuse of Storage Media

Before storage media is reassigned, the organization should determine whether previous information must be removed.

For example:

An employee leaves the company.

Their laptop is returned.

The laptop is given to another employee.

Simply deleting visible files may not be sufficient for every situation.

The organization should use an appropriate secure sanitization process based on the sensitivity of the information and the technology involved.


10. Secure Disposal of Storage Media

When storage media is no longer required, it should be disposed of securely.

Possible methods include:

  • Secure data erasure
  • Cryptographic erasure where appropriate
  • Physical destruction
  • Approved media destruction services
  • Certified disposal providers

The appropriate method depends on the sensitivity of the information and the type of media.

Where third parties are used, retain appropriate evidence such as:

  • Disposal records
  • Destruction certificates
  • Asset records
  • Vendor details
  • Chain-of-custody documentation

Startup Example

Imagine a 40-person SaaS company.

The company uses:

  • AWS for production
  • Google Workspace
  • Company laptops
  • Employee mobile phones
  • USB drives occasionally
  • External SSDs for certain IT activities
  • Automated cloud backups

The company does not need to create a complicated media-management program.

A practical approach could be:

Step 1 – Define the policy

Only authorized storage media may be used for company information.

Step 2 – Encrypt laptops

Company laptops use full-disk encryption.

Step 3 – Restrict USB use

USB storage is restricted through endpoint controls where the risk justifies it.

Step 4 – Protect sensitive exports

Database exports or security reports must not be copied to personal USB devices.

Step 5 – Control external drives

Company-approved external drives must be encrypted.

Step 6 – Secure disposal

Old laptops and storage devices go through an approved secure-erasure or destruction process.

Step 7 – Maintain evidence

The organization retains:

  • Asset records
  • Media disposal records
  • Encryption configuration
  • Relevant policies
  • Employee acknowledgement
  • Endpoint configuration evidence

Result:

Identify → Authorize → Protect → Use → Transport → Reuse → Securely Dispose


Storage Media Register

A startup can maintain a simple register.

Media IDTypeOwnerInformationClassificationEncryptionLocationStatus
MED-001External SSDITBackupConfidentialYesIT StorageActive
MED-002USBSecurityAudit reportsConfidentialYesSecure cabinetActive
MED-003Laptop SSDEmployeeBusiness dataInternalYesEmployeeActive
MED-004Backup DriveITBackup dataRestrictedYesBackup facilityRetired

Not every organization needs to register every individual storage component.

The level of inventory should be proportionate to risk and operational requirements.


Removable Media Authorization Matrix

ActivityEmployeeIT AdminSecurityManagement
Use approved USB✓✓✓✓
Copy confidential informationRestricted✓✓Approval
Create database exportNo✓✓Approval
Use personal USBNoNoNoNo
Dispose of storage mediaNo✓✓Approval
Authorize exceptionNoNo✓✓

The exact authorization model should be adapted to the organization’s size and risk.


Storage Media Risk Assessment

RiskLikelihoodImpactExample Control
USB lostMediumHighEncryption
Unauthorized USBMediumHighDevice control
Malware via USBMediumHighEndpoint protection
Backup stolenLowHighEncryption + secure storage
Improper disposalMediumHighSecure destruction
Data copied without authorizationMediumHighAccess/DLP controls
Media damagedLowHighEnvironmental protection
Unauthorized reuseMediumHighSecure sanitization

Storage Media Handling Procedure

A simple procedure can define:

Before use

  • Verify authorization
  • Verify approved device
  • Confirm classification
  • Apply encryption where required

During use

  • Do not leave media unattended
  • Do not connect unknown devices
  • Do not copy information unnecessarily
  • Follow acceptable-use requirements

During transportation

  • Protect against loss
  • Use secure packaging
  • Maintain authorization
  • Use encryption for sensitive information

After use

  • Return or securely store media
  • Delete temporary information where appropriate
  • Update records
  • Securely dispose of media when no longer required

Audit Evidence for Annex A 7.10

An auditor may request evidence such as:

Policies and procedures

  • Storage Media Policy
  • Acceptable Use Policy
  • Removable Media Procedure
  • Data Classification Policy
  • Information Transfer Procedure
  • Secure Disposal Procedure
  • Asset Management Procedure

Operational evidence

  • Storage media register
  • Asset inventory
  • USB/device control configuration
  • Encryption configuration
  • Endpoint management reports
  • Backup records
  • Media transportation records
  • Media disposal records
  • Destruction certificates
  • Secure erasure records
  • Exception approvals
  • Security awareness training records

Technical evidence

Depending on the environment:

  • Endpoint management screenshots
  • Device-control configuration
  • Encryption status
  • DLP policies
  • EDR configuration
  • USB restrictions
  • Mobile device management configuration

Audit Checklist – ISO 27001 Annex A 7.10

QuestionYes/NoEvidence
Has the organization identified storage media used to store information?
Are storage media classified according to information sensitivity?
Are removable media rules documented?
Is use of personal storage media controlled?
Are sensitive storage media appropriately protected?
Is encryption used where required?
Is transportation of sensitive media controlled?
Are backup media protected?
Is storage media protected from physical/environmental risks?
Is media reuse controlled?
Is sensitive information securely erased before reuse?
Is obsolete media securely destroyed or sanitized?
Are disposal records maintained where appropriate?
Are exceptions formally approved?
Are employees aware of storage media requirements?
Are controls periodically reviewed?

Common Mistakes

1. Treating USB drives as the only storage media

Storage media includes much more than USB drives.

Laptops, mobile devices, backup drives and other physical storage should also be considered.


2. Allowing personal USB devices

Employees may copy company information to personal storage devices without authorization.

This creates significant loss-of-control risk.


3. No encryption

Sensitive information stored on portable devices can be exposed if the device is lost or stolen.


4. No secure disposal process

Throwing an old hard drive into normal waste does not demonstrate appropriate information protection.


5. Ignoring backups

Backup media can contain some of the organization’s most sensitive information.


6. No process for lost devices

The organization should define what happens when:

  • USB drives are lost
  • Laptops are stolen
  • Backup media goes missing
  • External drives are misplaced

7. Creating excessive bureaucracy

A startup may create a 20-page storage media procedure that nobody follows.

The objective is effective protection, not documentation for its own sake.


8. Assuming cloud storage eliminates the requirement

Cloud storage can reduce the organization’s reliance on physical removable media, but organizations still have:

  • Laptops
  • Mobile devices
  • Local storage
  • Backups
  • External devices
  • Physical records

The organization should assess its actual environment.


Practical Startup Implementation Model

A startup can implement Annex A 7.10 using this model:

1. Identify

Identify storage media used by the organization.

2. Classify

Understand what information can be stored on it.

3. Authorize

Define who can use removable or portable media.

4. Protect

Use encryption, access control and endpoint security.

5. Transport

Protect media when it leaves the organization’s control.

6. Monitor

Monitor relevant use and exceptions where appropriate.

7. Reuse

Securely sanitize media before reassignment.

8. Dispose

Securely erase or destroy obsolete media.

9. Record

Maintain appropriate evidence.

10. Review

Periodically review whether the controls remain appropriate.

Startup formula: Know the media → Know the information → Control the use → Protect the data → Secure the disposal.


Policy vs. Process vs. Evidence

A common ISO 27001 mistake is confusing documentation with implementation.

LayerExample
PolicyStorage Media Policy
ProcessProcedure for approving, using and disposing of removable media
Technical ControlUSB restriction, encryption, endpoint control
RecordMedia register
EvidenceDisposal certificate
ReviewPeriodic storage media control review

An auditor is generally interested in whether the organization has implemented effective controls, not simply whether a policy exists.


Relationship With Other ISO 27001 Controls

Annex A 7.10 works closely with several other controls.

ControlRelationship
A.5.9 Inventory of Information and Other Associated AssetsHelps identify devices and storage assets
A.5.10 Acceptable UseDefines acceptable use of storage media
A.5.11 Return of AssetsCovers return of storage devices/assets
A.5.12 Classification of InformationDetermines protection based on information sensitivity
A.5.13 Labelling of InformationHelps identify information requiring protection
A.5.14 Information TransferRelevant when information is transferred using media
A.5.15 Access ControlRestricts access to information
A.5.18 Access RightsControls authorization
A.5.33 Protection of RecordsRelevant to records stored on media
A.5.34 Privacy and Protection of PIIImportant when media contains personal information
A.6.3 Awareness, Education and TrainingEmployees need to understand media risks
A.6.5 Responsibilities After TerminationRelevant when devices/media are returned
A.6.7 Remote WorkingRelevant when storage media is used outside the office
A.7.5 Physical and Environmental ThreatsProtects physical media from environmental risks
A.7.8 Equipment Siting and ProtectionProtects equipment containing storage
A.7.9 Security of Assets Off-PremisesProtects storage devices outside organizational premises
A.8.1 User Endpoint DevicesProtects laptops, desktops and similar devices
A.8.10 Information DeletionRelevant to secure deletion
A.8.13 Information BackupImportant for backup media
A.8.15 LoggingMay provide evidence of relevant activity

A.7.9 vs A.7.10

These controls are closely related but have different focuses.

ControlMain Focus
A.7.9 Security of Assets Off-PremisesProtecting assets when they are outside organizational premises
A.7.10 Storage MediaManaging and protecting media that stores information throughout its lifecycle

Example

An employee takes an encrypted company laptop home.

  • A.7.9 → protects the laptop and information while it is off-premises.
  • A.7.10 → addresses how the storage media containing information is managed and protected.

A.7.10 vs A.8.10 Information Deletion

These controls also complement each other.

A.7.10 focuses on managing storage media.

A.8.10 focuses on ensuring information is deleted when it is no longer required.

For example:

Old SSD → determine information sensitivity → securely erase information → verify appropriate sanitization → retire/dispose of SSD.

This combines media management with information deletion.


Useful Resources

Organizations can create practical supporting documents for Annex A 7.10.

Recommended documents

  1. Storage Media Policy
    [Insert Draft Document Link]
  2. Removable Media Procedure
    [Insert Draft Document Link]
  3. Storage Media Register
    [Insert Draft Document Link]
  4. Storage Media Risk Assessment
    [Insert Draft Document Link]
  5. USB / Removable Media Authorization Form
    [Insert Draft Document Link]
  6. Storage Media Disposal Procedure
    [Insert Draft Document Link]
  7. Media Sanitization Record
    [Insert Draft Document Link]
  8. Media Destruction Certificate Template
    [Insert Draft Document Link]
  9. Backup Media Register
    [Insert Draft Document Link]
  10. Storage Media Audit Checklist
    [Insert Draft Document Link]

Questions an Auditor May Ask

An auditor may ask:

1. What types of storage media does your organization use?

Be prepared to explain laptops, mobile devices, backup media, USB drives, external drives and other relevant media.

2. Can employees use personal USB devices?

Explain your policy and technical controls.

3. How do you protect sensitive information stored on removable media?

Explain encryption and access restrictions.

4. What happens when a storage device is lost?

Explain the incident-reporting and response process.

5. How do you dispose of old hard drives?

Show your secure disposal/sanitization process.

6. How do you handle backup media?

Explain storage, encryption, access, retention and disposal.

7. How do you prevent unauthorized copying?

Explain endpoint controls, permissions, DLP or other relevant measures.

8. How do you handle media containing personal information?

Explain classification, access, protection, retention and secure deletion.

9. How do you know storage media was securely destroyed?

Provide destruction or sanitization records where applicable.

10. How are employees trained?

Show awareness or training records covering acceptable use and information handling.


Startup-Focused Final Takeaway

ISO 27001 Annex A 7.10 is not about creating a complicated inventory of every hard drive in the organization.

It is about maintaining control over information stored on physical and removable media throughout its lifecycle.

A practical startup approach is:

Identify → Classify → Authorize → Protect → Transport → Store → Reuse Safely → Dispose Securely → Review

Before implementing this control, ask:

  • What storage media do we actually use?
  • What information can be stored on it?
  • Which information is sensitive?
  • Who is authorized to use it?
  • Is sensitive data encrypted?
  • What happens when media is lost?
  • What happens when media is reused?
  • What happens when media is no longer required?
  • Can we demonstrate these controls to an auditor?

The simple rule

If information can be stored on it, the organization should have an appropriate way to protect it.

For startups, the goal is not to eliminate every storage medium.

The goal is to ensure that information does not lose its protection simply because it was moved from a cloud system to a laptop, USB drive, external disk, backup device, or other storage medium.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *