The ultimate audit guide to ISO 27001 Annex A 7.14 Secure Disposal or Re-Use of Equipment
Table of contents
- 1. Equipment Disposal Policy Formalisation Verified
- 2. Media Sanitisation Methodology Alignment Confirmed
- 3. Data Destruction Certification Presence Validated
- 4. Internal Re-use Sanitisation Records Identified
- 5. Physical Destruction of Damaged Media Confirmed
- 6. Secure On-site Storage of E-Waste Verified
- 7. Vendor Vetting and Environmental Compliance Validated
- 8. Cloud Instance and Virtual Asset Decommissioning Verified
- 9. Maintenance of Disposal Chain of Custody Confirmed
- 10. Management Review of Disposal Trends Recorded
1. Equipment Disposal Policy Formalisation Verified
Verification Criteria: A documented policy exists defining the mandatory security requirements for the disposal or re-use of equipment containing storage media.
Required Evidence: Approved Asset Disposal Policy or Data Sanitisation Standard with explicit version control.
Pass/Fail Test: If the organisation cannot produce a formal policy specifying how data must be erased before equipment leaves the premises, mark as Non-Compliant.
2. Media Sanitisation Methodology Alignment Confirmed
Verification Criteria: Data erasure methods are aligned with recognised international standards (e.g. NIST 800-88 or HMG IS5) based on the classification of the data previously held.
Required Evidence: Technical configuration logs of sanitisation software or service level agreements (SLAs) with disposal vendors citing specific standards.
Pass/Fail Test: If the organisation uses standard OS “Format” commands rather than cryptographic erasure or multi-pass overwriting for sensitive assets, mark as Non-Compliant.
3. Data Destruction Certification Presence Validated
Verification Criteria: Every piece of disposed equipment containing media is supported by a unique certificate of destruction or erasure.
Required Evidence: Asset disposal folder containing certificates cross-referenced against the Master Asset Register serial numbers.
Pass/Fail Test: If a sampled asset is marked as ‘Disposed’ in the register but lacks a corresponding destruction certificate, mark as Non-Compliant.
4. Internal Re-use Sanitisation Records Identified
Verification Criteria: Equipment repurposed for a different department or user undergoes a verified data wipe to prevent unauthorised internal data spill.
Required Evidence: IT ticket logs or technician sign-off sheets confirming sanitisation before the asset was re-imaged and re-issued.
Pass/Fail Test: If an asset is transferred between users without a recorded sanitisation step, mark as Non-Compliant.
5. Physical Destruction of Damaged Media Confirmed
Verification Criteria: Storage media that cannot be electronically wiped due to hardware failure is subjected to physical destruction (shredding, crushing, or incineration).
Required Evidence: Photos of crushed media or waste transfer notes from a certified physical destruction provider.
Pass/Fail Test: If faulty hard drives are stored in unsecure “e-waste” bins without being physically rendered unreadable, mark as Non-Compliant.
6. Secure On-site Storage of E-Waste Verified
Verification Criteria: Equipment awaiting disposal or collection is stored in a secure, restricted-access area to prevent opportunistic theft of data.
Required Evidence: Physical sighting of a locked room or secure cage designated for “Assets Awaiting Destruction.”
Pass/Fail Test: If decommissioned laptops or servers are found in an open-access hallway or unlocked basement, mark as Non-Compliant.
7. Vendor Vetting and Environmental Compliance Validated
Verification Criteria: Third-party disposal contractors are vetted for security competency and hold relevant environmental and security certifications.
Required Evidence: Valid ISO 27001 or ADISA (Asset Disposal & Information Security Alliance) certification for the disposal partner.
Pass/Fail Test: If the disposal vendor lacks an active security certification or a formal data processing agreement (DPA), mark as Non-Compliant.
8. Cloud Instance and Virtual Asset Decommissioning Verified
Verification Criteria: Decommissioning of virtual equipment (instances/storage buckets) includes the secure deletion of data and removal of all access keys.
Required Evidence: Cloud provider logs (e.g. AWS CloudTrail) showing resource termination and cryptographic key revocation.
Pass/Fail Test: If a virtual server is terminated but its associated unencrypted snapshots or backups remain active, mark as Non-Compliant.
9. Maintenance of Disposal Chain of Custody Confirmed
Verification Criteria: A documented chain of custody exists for all equipment from the point of decommissioning to the final point of destruction.
Required Evidence: Signed collection manifests showing the number of items and serial numbers transferred to the disposal vendor.
Pass/Fail Test: If the organisation cannot prove exactly which serial numbers were handed over to the courier, mark as Non-Compliant.
10. Management Review of Disposal Trends Recorded
Verification Criteria: Annual reviews of the disposal process are conducted to ensure no assets are “lost” and that the vendor is meeting security obligations.
Required Evidence: Management Review Meeting (MRM) minutes or Audit Reports specifically addressing asset disposal metrics.
Pass/Fail Test: If the organisation has not performed a reconciliation between “Retired” assets and “Destroyed” certificates in the last 12 months, mark as Non-Compliant.