ISO 27002:2022
Physical controls – ISO 27002:2022

ISO 27002:2022 7.10: Storage media

Storage media are to be controlled through acquisition, use, transport and disposal in line with how the organization classifies information and the handling rules that follow. Purpose: allow information on storage media to be disclosed, changed, removed or destroyed only with authorization. Guidance for removable media: set a topic-specific policy on removable media and tell everyone who uses or handles it; where needed and practical, require authorization to take media out of the organization and record removals as an audit trail; keep media in a safe environment matching their classification and protected, per manufacturer specifications, from heat, moisture, humidity, electromagnetic fields and ageing; encrypt information on removable media where confidentiality or integrity matters; copy information to fresh media before old media degrade while the information is still needed; keep several copies of valuable information on separate media to reduce the chance of losing it all at once; consider registering removable media to limit loss; enable media ports such as SD slots and USB ports only when there is a business reason; monitor information copied to removable media where its use is necessary; and remember that information in physical transit by post or courier can be accessed, misused or corrupted. Paper counts as media here, and 5.14 applies when media are moved. Reuse and disposal: set procedures, proportionate to sensitivity, to limit leakage of confidential information: securely erase or format media before internal reuse (8.10); securely dispose of media no longer needed by destruction, shredding or secure deletion; identify which items need secure disposal; choose external collection and disposal providers with adequate controls and experience; log disposal of sensitive items for an audit trail; and consider that aggregating large amounts of non-sensitive media for disposal can make the whole sensitive. Damaged devices holding sensitive data should be risk assessed to decide whether to destroy them rather than repair or discard them (7.14). Other information: unencrypted confidential media may need extra physical protection.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 89 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CMMC 2.0 · 8 controls

PCI DSS 4.0 · 8 controls

  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media
  • 9.4.1.1 9.4.1.1 Secure storage location for offline backups
  • 9.4.1.2 9.4.1.2 Annual review of offline backup location security
  • 9.4.2 9.4.2 Classification of media by data sensitivity
  • 9.4.3 9.4.3 Securing media sent outside the facility
  • 9.4.5 9.4.5 Inventory logs of electronic media
  • 9.4.6 9.4.6 Destruction of hard-copy materials
  • 9.4.7 9.4.7 Destruction of electronic media

NIST SP 800-53 Rev 5 · 7 controls

  • ISM-0374 Media disposal process and procedures
  • ISM-0831 Handling media by sensitivity or classification
  • ISM-0835 TOP SECRET volatile media after sanitisation
  • ISM-1418 Blocking reads from removable media
  • ISM-1549 Media management policy
  • ISM-1713 Removable media register

CIS Controls v8 · 5 controls

  • CIS-10.3 Disable Autorun and Autoplay for Removable Media
  • CIS-11.3 Protect Recovery Data
  • CIS-3.11 Encrypt Sensitive Data at Rest
  • CIS-3.5 Securely Dispose of Data
  • CIS-3.9 Encrypt Data on Removable Media

FedRAMP High · 5 controls

FedRAMP Moderate · 5 controls

  • NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk

SOC 2 · 5 controls

  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-P4.3 P4.3 Securely disposing of personal information

NIST SP 800-171 Rev 3 · 4 controls

HIPAA Security Rule · 3 controls

ISO/IEC 27037:2012 · 3 controls

  • 6.9.2 6.9.2 Preserving potential digital evidence
  • 6.9.3.2 6.9.3.2 Additional activities: packaging of potential digital evidence
  • 7.1.3.5 7.1.3.5 Digital storage media

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

C5 (Germany) · 2 controls

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy
  • C5-AM-04 Decommissioning of Hardware

ISO 27001:2022 · 2 controls

  • 7.10 Storage media
  • 7.9 Security of assets off-premises
  • ANSSI-HYG-15 Protect Against Threats Related to Removable Media
  • ASD37-13 Control removable storage media (Very Good)

ISO 27701:2019 · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-7.10 Storage Media Handling in Telecoms

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management
  • P1-6.2.1 P1-6.2.1 Strict control over media storage and access
  • 0073 0073 Dispose of information securely
  • MTSA-Removable-Media Removable Media and Portable Device Controls

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Physical controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 7.10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 89 it maps to, and the evidence behind each claim, over MCP and REST.