ISO 27001:2022 Annex A 7.10 Storage Media Explained

ISO 27001 Annex A 7.10 Storage Media

In this guide you will learn how to implement ISO 27001 Annex A 7.10 and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 7.10 Storage Media is an ISO 27001 control that looks to protect storage media.

Purpose & Definition

The purpose of ISO 27001 Storage Media is to ensure only authorised disclosure, modification, removal or destruction of information on storage media.

The ISO 27001 standard defines ISO 27001 Annex A 7.10 as:

Storage media should be managed through their life cycle of acquisition, use, transportation and disposal in accordance with the organisations classification scheme and handling requirements.

ISO 27001:2022 Annex A 7.10 Storage Media

FREE ISO 27001 Annex A 7.10 Training Video

In this free training video you will learn How to implement ISO 27001 Storage Media (Annex A 7.10) and Pass Your Audit.

Implementation Guide

General Guidance

There is one thing that people don’t really trust like they used to, and that is external storage media. This control is looking at all types of storage media with a particular focus on removable / external storage media.

Let us first look in general terms before we give some attention to removable media and its particular challenges.

ISO 27001 Information Security Classification and Handling Policy

You will want a policy in place on Data Classification and Handling that will cover storage media, for example the Information Security Classification and Handling Policy. This is to set out and communicate what the expectations are that you have of people.

ISO 27001 Information Classification and Handling Policy - ISO 27001 Annex A 7.10 Template
ISO 27001 Information Classification and Handling Policy Template

Lifecycle Management Process

Then you are going to put in full lifecycle management of the storage media. Even if it comes bundled as part of other devices.

What this means in real terms is having a process for:

How you acquire storage media, where you acquire it from, how you configure it, if and how you encrypt it, how you use it, where you use it, who is responsible for it, how you monitor it, and at its end of life how you destroy it.

To all intents and purposes, storage media is an asset under asset management.

Reuse and destruction of storage media has its own requirements. Let’s not be just deleting stuff and then popping it on eBay. If you have to reuse it then securely destroy the data on it in a proper and professional way. If you have to destroy it, whilst hitting with a FBH ( fking big hammer ) can work wonders, ideally use a reputable outsourced destruction company that provides all the required paperwork and audit trails.

Removable Storage Media

In general terms you are going to implement a topic specific policy on the use and management of removable media. What this means is addressing it in one of your other policies. As long as it is covered you are fine.

Think here about what kind of media you will allow. What the process is for allowing it. That can be both a technical processes such as port lockdowns and / or administrative process such as approval and checking.

Physical security of removable storage is paramount. A no brainer when you think about it. It is harder to steal. Harder to track. Easier to lose. Implement controls based on risk and the classification of what the storage media contains.

One thing people often overlook is that media has life span and will degrade over time. There are approaches to having multiple copies and / or multiple storage technologies. All of this will really be driven by your data retention requirements but worth thinking about.

Paper

Finally paper is storage media. If you have it, risk assess it and control it based on risk and business need. Fewer and fewer organisations rely on paper these days but it is still out there. Usually in regulated industries. If you have it, don’t over look it.

How to implement ISO 27001 Annex A 7.10

Implementing ISO 27001 Annex A 7.10 requires a robust lifecycle management process for all physical and virtual storage media.

1. Formalise a Storage Media Handling Policy

Develop and approve a topic-specific policy that defines the mandatory security requirements for all media types, providing a regulatory foundation for the Information Security Management System (ISMS).

  • Define the scope of media covered, including USB drives, SSDs, backup tapes, and cloud storage volumes.
  • Establish clear rules for the use of personal removable media (BYOD) within the organisation.
  • Specify the required security classifications and corresponding handling instructions for sensitive data.
  • Document the roles and responsibilities for asset owners and system administrators.

2. Provision Technical Endpoint Restrictions

Deploy technical controls to prevent the unauthorised use of removable media, reducing the risk of malware infection and data exfiltration.

  • Implement Unified Endpoint Management (UEM) policies to block unapproved USB devices at the hardware level.
  • Enforce mandatory Full Disk Encryption (FDE) using AES-256 for any media permitted to leave secure zones.
  • Configure automated logging for all data transfer events to removable storage for audit trail purposes.
  • Restict write access to removable media to only authorised IAM roles or specific user groups.

3. Establish Secure Storage and Transport Protocols

Ensure that media is protected from physical damage, environmental hazards, and unauthorised interception during storage and transit.

  • Utilise fireproof and waterproof safes for the long term storage of physical backup media.
  • Mandate the use of tamper-evident packaging and tracked courier services for physical media transport.
  • Maintain a formal sign-in and sign-out log for all media entering or leaving secure areas.
  • Verify the integrity of received media before it is connected to the organisational network.

4. Execute Managed Sanitisation and Disposal

Render data unrecoverable on retired media using verified technical methods to prevent data breaches via the secondary market.

  • Apply NIST 800-88 compliant sanitisation techniques such as “Clear” or “Purge” for media intended for re-use.
  • Provision physical destruction services, such as industrial shredding or incineration, for end-of-life hardware.
  • Obtain a formal Certificate of Destruction (CoD) for every asset that is physically destroyed.
  • Document the disposal method and date within the central Asset Register to maintain audit evidence.

5. Conduct Regular Asset Inventory Audits

Perform periodic reviews of all storage media to ensure that all assets are accounted for and that security controls remain effective.

  • Cross-reference physical media in storage against the digital Asset Register.
  • Audit encryption status on a sample of active removable devices to ensure compliance.
  • Review transfer logs to identify unusual patterns or unauthorised data movements.
  • Revoke access rights for any media identified as lost or stolen within the Incident Management framework.

How to comply

To comply with ISO 27001 Annex A 7.10 Storage Media you are going to

  • Train, educate, tell and communicate to people what is expected of them
  • Have policies and procedures in place
  • Assess your assets and perform a risk assessment
  • Implement controls proportionate to the risk posed
  • Test the controls that you have to make sure they are working

Top 3 mistakes and how to avoid them

The top 3 mistakes people make for ISO 27001 Annex A 7.10 Storage Media are

  • You have loads of hard drives in a cupboard: This is the number one mistake. Having computers, hard drives, old devices, paper archives that no one knows what they are, what is on them or why you have them either in a store room or worse case on someones desk. Get your asset management sorted. Get your house in order. Do your house keeping.
  • One or more members of your team haven’t done what they should have done: Prior to the audit check that all members of the team have done what they should have. Do they know where the policies are? Have they acknowledged them? Do you have an inventory of storage media? Is removable media managed, tracked and checked? Check!
  • Your document and version control is wrong: Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.

ISO 27001 Annex A 7.10 FAQ

What is considered storage media under ISO 27001?

Under ISO 27001, storage media refers to any physical or virtual object used to store data, including removable hardware and digital storage environments.
Removable media: USB flash drives, external hard drives (HDD/SSD), and SD cards.
Fixed media: Internal server drives and workstation hard disks.
Legacy media: Tapes, optical discs (CD/DVD), and printed paper records.
Virtual media: Cloud storage buckets, virtual disks, and backup snapshots.

Does ISO 27001 require encryption for all removable media?

Yes, while the standard does not explicitly name technology, encryption is the industry-standard technical control required to mitigate the risk of data compromise on removable media.
Enforce full-disk encryption for all USB drives and external SSDs.
Utilise AES-256 or higher encryption standards for sensitive data.
Implement centralised management to ensure encryption is active on all endpoints.
Mandate encryption for any data being transported outside of secure zones.

How should storage media be disposed of securely?

Secure disposal requires rendering data unrecoverable through physical destruction or verified sanitisation techniques before the media leaves organisational control.
Physical Destruction: Shredding, pulping, or incineration of hard drives and tapes.
Sanitisation: Using software to “Purge” or “Clear” data based on NIST 800-88 standards.
Degaussing: Using high-strength magnets to erase magnetic media like tapes or HDDs.
Documentation: Obtaining and filing Certificates of Destruction (CoD) for audit evidence.

What are the requirements for transporting physical media?

Transporting physical media requires strict chain-of-custody controls to prevent interception, theft, or environmental damage during transit.
Use authorised, tracked courier services with tamper-evident packaging.
Ensure all data on the media is encrypted prior to transport.
Keep a log of all media leaving and entering secure perimeters.
Verify the identity of the recipient upon delivery.

How do organisations manage the use of removable media?

Management is achieved through a combination of policy restrictions, technical blocks, and user awareness training.
Restrict the use of unauthorised personal USB devices via endpoint management software.
Establish a “Removable Media Policy” that users must sign and follow.
Log all data transfers to removable media for monitoring and incident response.
Audit the inventory of physical media assets at regular intervals.

There are a couple of other related controls worth reading up here as well being

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top