Storage media are to be controlled through acquisition, use, transport and disposal in line with how the organization classifies information and the handling rules that follow. Purpose: allow information on storage media to be disclosed, changed, removed or destroyed only with authorization. Guidance for removable media: set a topic-specific policy on removable media and tell everyone who uses or handles it; where needed and practical, require authorization to take media out of the organization and record removals as an audit trail; keep media in a safe environment matching their classification and protected, per manufacturer specifications, from heat, moisture, humidity, electromagnetic fields and ageing; encrypt information on removable media where confidentiality or integrity matters; copy information to fresh media before old media degrade while the information is still needed; keep several copies of valuable information on separate media to reduce the chance of losing it all at once; consider registering removable media to limit loss; enable media ports such as SD slots and USB ports only when there is a business reason; monitor information copied to removable media where its use is necessary; and remember that information in physical transit by post or courier can be accessed, misused or corrupted. Paper counts as media here, and 5.14 applies when media are moved. Reuse and disposal: set procedures, proportionate to sensitivity, to limit leakage of confidential information: securely erase or format media before internal reuse (8.10); securely dispose of media no longer needed by destruction, shredding or secure deletion; identify which items need secure disposal; choose external collection and disposal providers with adequate controls and experience; log disposal of sensitive items for an audit trail; and consider that aggregating large amounts of non-sensitive media for disposal can make the whole sensitive. Damaged devices holding sensitive data should be risk assessed to decide whether to destroy them rather than repair or discard them (7.14). Other information: unencrypted confidential media may need extra physical protection.
This control maps to 89 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
ISO 27002:2022 7.10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.
The graph holds this control, the 89 it maps to, and the evidence behind each claim, over MCP and REST.