ISO 27001 Annex A 7.10 Storage Media controls how teams manage storage media from purchase to disposal. Written safety rules prevent data leaks and block unapproved access to portable devices.
Table of contents
Key Takeaways
- Manage media lifecycles: Create clear rules for how staff buy, use, move, and destroy all storage devices.
- Store rules centrally: Keep clear policy files and media logs in a central document repository to prove accountability.
- Encrypt removable media: Require strong code protection on all portable drives to stop data leaks if lost or stolen.
- Secure physical transport: Use locked bags and trusted couriers when moving physical storage drives between site locations.
- Sanitise or destroy media: Wipe data fully or shred old drives before reuse or disposal to prevent data recovery.
- Restrict media access: Limit access to removable storage units so only approved workers handle sensitive files.
- Maintain media inventories: Keep an active log of all physical and portable storage items to track asset ownership.
- Store media in safe areas: Keep backup tapes and portable drives in locked, fireproof safes inside secure rooms.
How to Implement ISO 27001 Annex A 7.10
- Draft media handling rules: Write a clear media policy and store it in your central document repository.
- Enforce drive protection: Set strict encryption requirements for all removable and portable storage items.
- Maintain a central media register: Build a simple tracking list to record all physical storage devices and their owners.
- Log disposal and transport requests: Use a central task system to log every media movement or destruction event.
- Schedule routine log reviews: Review device tracking logs during regular management meetings to spot missing items fast.
- Secure physical media storage: Keep spare drives and backup media inside locked, fireproof safes in restricted access areas.
- Train staff on media risks: Teach workers safe handling habits for portable drives, including clean desk and clear screen rules.
- Get disposal certificates: Obtain signed destruction receipts whenever external vendors shred or wipe old storage drives.
- Restrict port access: Block unapproved USB ports on company hardware to stop staff from attaching unknown storage devices.
How to Audit ISO 27001 Annex A 7.10
- Review media management policies: Inspect written rules to confirm clear guidance exists for buying, using, moving, and destroying storage items.
- Audit the central media register: Sample entries in the inventory log to verify all physical and portable storage items match real assets.
- Verify media encryption settings: Inspect sample portable drives to ensure strong code protection guards all data on removable storage devices.
- Inspect physical storage safes: Check that spare drives and backup media stay locked inside fireproof safes in restricted zones.
- Check media disposal receipts: Sample destruction logs to confirm signed certificates exist for all shredded or wiped storage items.
- Review transit protection controls: Check transport logs to ensure staff use locked bags and secure couriers when moving storage off site.
- Verify port restriction controls: Test sample work computers to ensure system locks block unapproved storage hardware.
- Audit media reuse procedures: Confirm staff wipe media completely before reissuing storage items to new users.
- Review contractor disposal agreements: Check active contracts with third-party destruction vendors to confirm secure handling guarantees.
- Inspect physical access logs: Check sign-in records for media storage rooms to verify only approved staff gain access.
- Review lost media incident logs: Inspect report tickets for missing drives to confirm teams ran full risk checks and reported leaks fast.
- Verify staff training records: Confirm employees complete regular security awareness training on safe media handling and clear desk rules.
- Check environmental controls for storage: Verify media safes and storage rooms maintain proper climate levels to prevent physical drive decay.
- Review media classification labels: Check physical media labels to ensure staff mark sensitive items clearly according to data safety rules.
Audit Evidence Checklist
- Media handling policy: Maintain a documented media handling policy with a complete version history in your central document repository.
- Storage media register: Keep an active, up-to-date inventory list of all physical and portable storage media assets and owners.
- Decommissioning tickets: Supply task management records showing the formal sanitisation and retirement of old storage drives.
- Destruction certificates: Provide signed disposal receipts from licensed service providers to prove safe physical media destruction.
- Physical audit reports: Produce internal review logs that verify physical storage locations and secure safe conditions.
- Transport and courier logs: Keep signed chain of custody forms for all physical storage devices moved off site.
- Media encryption verification logs: Maintain audit records showing that all portable drives carry active, mandatory encryption.
- Staff training logs: Show sign-off sheets proving employees completed security awareness training on safe media handling.
What to Teach Employees
- Encrypt all portable media: Teach workers that all removable storage items must carry full drive encryption before saving any work files.
- Lock away unused storage drives: Instruct staff to keep memory sticks, external hard drives, and backup tapes in locked drawers or safes when not in use.
- Never use unknown storage devices: Warn employees never to plug found or unapproved flash drives into company computers or equipment.
- Log new storage assets: Train workers to register every new physical storage device in the central inventory log before using it.
- Follow secure transit steps: Instruct staff to use approved locked pouches or secure courier services when moving physical storage items off site.
- Hand in old media for disposal: Remind workers to return old, broken, or unwanted storage drives to the IT team for safe sanitisation and disposal.
- Keep clear desk areas: Teach staff to clear desks of all removable drives, paper files, and backup media before leaving their work areas.
- Label sensitive media clearly: Instruct team members to place clear physical data labels on storage drives carrying confidential information.
- Report missing media fast: Ensure employees know to report lost or stolen storage drives immediately to limit data breach risks.
- Wipe media before reuse: Remind staff never to pass a used storage drive to another worker without fully erasing all existing files first.
- Avoid personal storage items: Warn staff against storing company files on personal, unmanaged external hard drives or personal devices.
- Understand media lifecycle rules: Train workers on how poor media handling leads to data leaks, regulatory fines, and business damage.
Common Implementation Challenges
- Unapproved storage usage: Staff plug personal storage items into work computers. Enforce system port controls to block unknown devices and restrict save rights.
- Incomplete media registers: Teams swap or loan portable drives without updating tracking lists. Run regular physical asset checks to keep inventory registers accurate.
- Unencrypted portable storage: Staff save sensitive files onto unencrypted external drives that get lost or stolen. Mandate full code protection for all removable storage.
- Unsafe device re-use: Teams pass old portable drives or equipment to new staff without clearing files. Enforce full wiping steps before hardware changes hands.
- Missing disposal receipts: Broken or old drives go into waste bins without proof of destruction. Require signed disposal receipts from certified destruction vendors.
- Overlooking paper records: Teams focus on digital drives and ignore paper files. Treat confidential paper notes as storage media subject to safe shredding.
- Unsecure media in transit: Staff carry storage drives off site in personal bags without protection. Require locked bags and tracked couriers when moving physical media.
- Unlocked physical storage: Spare backup media and extra drives stay in open office drawers. Keep offline storage locked in fireproof safes inside secure rooms.
- Physical media decay: Old storage drives break down over time and lose data. Set planned refresh cycles to copy critical files to new media regularly.
- Poor remote worker tracking: Off-site staff buy local external drives without approval. Set clear policy rules and supply approved, encrypted storage for remote teams.
- Lack of media safety checks: Outside storage items bring threats into company networks. Require all external media to pass security scans before opening files.
- Delayed loss reporting: Staff wait days to report lost storage drives out of fear. Build a blameless culture so workers report missing drives right away.
- Unmonitored third-party vendors: External disposal services collect old drives without clear tracking. Require double sign-offs for all media handover events.
- Excessive data hoarding: Teams keep old drives forever instead of clearing them. Set clear retention limits to ensure timely sanitisation and disposal.
- Unlabeled sensitive media: Workers fail to mark storage items containing confidential data. Require clear physical safety labels on all sensitive media assets.
- Missing physical access controls: Unapproved workers enter areas where physical storage media stays stored. Limit room access to key staff to protect physical drives.
How to Measure Effectiveness (KPIs)
- Media encryption coverage rate: Measure the percentage of active portable storage devices that carry full code protection.
- Media register accuracy rate: Track the proportion of physical storage drives that match tracking records during quarterly inventory checks.
- Disposal certificate compliance rate: Measure the percentage of retired storage devices with signed destruction receipts on file.
- Lost media incident rate: Track the number of lost, stolen, or misplaced removable storage items reported each year.
- Media loss reporting speed: Monitor the average time taken by staff to report missing storage hardware after noticing the loss.
- Unapproved media block rate: Track the number of unapproved external drive connection attempts blocked by system port controls.
- Safe storage lock compliance: Measure the percentage of offline backup media and spare drives kept locked inside fireproof safes.
- Media transit log compliance: Track the proportion of off-site media transfers that carry full chain of custody signatures.
- Media sanitisation pass rate: Measure the percentage of reissued storage devices that pass full data wipe checks before new assignment.
- Storage media audit finding count: Monitor the number of security gaps flagged during internal reviews of physical and digital storage controls.
- Media awareness training rate: Track the percentage of workers who finish annual training on safe storage media handling.
- Physical media label compliance: Measure the proportion of storage drives correctly marked with data sensitivity labels during spot checks.
Related ISO 27001 Controls
ISO 27001 Control A 7.10 connects to several other ISO 27001 requirements:
- ISO 27001 Clause 8.1 (Operational Planning): Directs the management of media lifecycles.
- ISO 27001 Annex A 5.9 (Inventory of Information): Provides the basis for the media register.
- ISO 27001 Annex A 8.10 (Information Deletion): Governs the digital cleansing of media.


