A.7.10A.7 Physical controls

Storage media

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.7.10 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Manage storage media across its life cycle so information is only disclosed, changed, removed or destroyed by authorised parties.

How to meet this control

In short: Manage media through acquisition, use, transport and disposal.

  1. Step 01Publish a removable-media policy and, where there is no business need, disable USB and SD storage ports through MDM or endpoint controls
  2. Step 02Where removable media is permitted, require encryption, log its use and authorise and record any media leaving the premises
  3. Step 03Store media in conditions matched to its classification, protected from heat, moisture and degradation
  4. Step 04Migrate information to fresh media before old media degrades beyond readability, for long-retention data
  5. Step 05For reuse, securely wipe or reformat media first, and for disposal destroy or securely erase it and log the outcome
  6. Step 06Account for the aggregation effect when media accumulates, so a batch awaiting disposal is protected to the level of the most sensitive item

Tip: Track removable media and encrypt it; many orgs simply prohibit USB storage.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Set and communicate a policy for managing removable media, including paper documents
  • ›Require authorisation and keep records when media is removed from the organisation
  • ›Store media in a safe environment matched to its classification and protected from heat and moisture
  • ›Use encryption on removable media when confidentiality or integrity matters
  • ›Transfer information to fresh media before old media degrades beyond readability
  • ›Only enable USB and SD ports where there is a business reason, and monitor transfers
  • ›For reuse, securely delete or format media first; for disposal, destroy or securely erase and log it
  • ›Consider the aggregation effect when accumulating media for disposal

Audit evidence to keep

  • - The storage-media or removable-media policy
  • - Endpoint configuration showing USB or port restrictions
  • - A register tracking removable media and authorised removals
  • - Secure-wipe or destruction logs for disposed media
  • - Records showing encryption applied to removable media

Common mistakes

  • - Relying on office trust without logs
  • - Not tracking assets used away from the office
  • - Disposing equipment without wipe or destruction evidence

Owner, cadence, and proof

Assign one accountable owner for A.7.10. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all physical controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.