A7.10 Storage media
4 min read
Storage media—including hard drives, USB flash drives, CDs/DVDs, SD cards, and even cloud-based media—often contain sensitive business data. Improper handling, storage, or disposal of such media can lead to data loss, leaks, or unauthorized access.
ISO 27001 A7.10 Storage media emphasizes the need to manage storage media throughout its lifecycle—from creation and use to transfer, retention, and disposal. Whether physical or digital, storage media must be protected based on the sensitivity of the information it holds. This is especially crucial for portable media, which is easily lost or stolen.
Proper storage media management helps organizations reduce the risk of breaches, maintain data integrity, and comply with regulatory requirements like GDPR, HIPAA, and PCI DSS.
Implementation Guide #
Step 1: Define Acceptable Media Types and Usage Policies
- List approved storage media types for business use.
- Prohibit or restrict unapproved or personal media (e.g., personal USB drives).
- Set rules for encrypting media that stores confidential or restricted data.
Step 2: Protect Storage Media in Use
- Apply encryption to sensitive data stored on portable or removable media.
- Limit access to authorized personnel only.
- Prevent unauthorized duplication or distribution of data.
Step 3: Track and Monitor Media Movement
- Keep a log of storage media issued, transferred, or received.
- Use tamper-evident packaging when sending media off-site.
- Establish chain-of-custody procedures for high-risk data.
Step 4: Ensure Secure Storage and Retention
- Store physical media in locked cabinets or secure data rooms.
- Define retention periods based on legal, business, or regulatory requirements.
- Avoid storing outdated or unnecessary media.
Step 5: Dispose of Media Securely
- Use data destruction techniques such as degaussing, shredding, or secure erasure.
- Document disposal activities to maintain audit trails.
- Verify that cloud or virtual storage media are sanitized when decommissioned.
Templates #
- Storage Media Handling Policy
- Media Encryption and Access Control Procedure
- Storage Media Inventory Log
- Media Transfer Authorization Form
- Secure Disposal Checklist and Log
Example #
An employee transfers customer data to a USB drive to prepare a report at home. The USB drive is later misplaced in public transport. However, due to encryption and password protection, no data is compromised. The incident is reported, and the drive is marked as lost in the media inventory.
If the drive were unencrypted, the organization could have faced a serious data breach and potential legal penalties.
How to Comply #
To comply with ISO 27001 A.7.10, organizations should:
- Define usage, transfer, and disposal procedures for all types of storage media.
- Use encryption and access controls for sensitive data on media.
- Maintain media logs and records.
- Train employees on media handling procedures.
- Dispose of obsolete or damaged media using approved destruction methods.
How to Pass an Audit #
Key Documents to Prepare:
- Storage Media Handling Policy
- Media Transfer and Disposal Logs
- Encryption Configuration Documentation
- Employee Training Records
- Evidence of Secure Disposal (e.g., certificates or destruction logs)
What the Auditor Will Check:
- Are there documented procedures for handling storage media?
- Are media containing sensitive data encrypted and access-controlled?
- Is there evidence that media disposal follows secure methods?
- Are employees aware of the risks and trained in safe handling?
Top 3 Mistakes People Make #
- Using unencrypted storage media for sensitive data.
- Failing to log or track media transfers, especially removable media.
- Disposing of media without verifying complete data destruction.
ISO 27001 Storage Media FAQ #
Q1: Can employees use personal USB drives for work?
Generally, no. Only organization-approved media should be used to avoid security risks, unless personal devices are scanned, encrypted, and monitored as per policy.
Q2: Is cloud storage considered storage media?
Yes. Cloud services are considered a form of virtual storage media and should follow the same principles—especially regarding encryption, access control, and secure deletion.
Q3: How often should media disposal procedures be reviewed?
At least annually or when regulations or organizational requirements change.
#
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.7.10 Storage Media | Preventive, Risk-Based, Operational |
| Purpose | Prevent unauthorized access, loss, or disclosure of data stored on media |
| Applicability | All departments using digital or physical storage devices |
| ISO 27001 Domains | Asset Management, Operations Security, Data Protection |
By managing storage media securely—from use to disposal—organizations can protect sensitive data and reduce the likelihood of leaks or breaches. Neglecting this control opens doors to accidental exposure, reputational harm, and regulatory penalties.