ISO 27002:2022
Physical controls – ISO 27002:2022

ISO 27002:2022 7.14: Secure disposal or re-use of equipment

Before equipment containing storage media is disposed of or reused, it is to be checked to confirm that sensitive data and licensed software have been removed or securely overwritten. Purpose: stop information leaking from equipment that is disposed of or reused. Guidance: check whether equipment contains storage media before disposal or reuse. Where media hold confidential or copyright material, either the media are destroyed physically or the data is destroyed, deleted or overwritten with techniques that make it unrecoverable instead of a standard delete (see 7.10 for media disposal and 8.10 for deletion). Remove labels and markings that identify the organization or show classification, owner, system or network before disposal, including resale or charitable donation. At the end of a lease or when moving out, consider removing security controls such as access control or surveillance equipment, depending on lease terms to restore the premises, the chance that systems holding sensitive data are left behind such as user access lists or video for the next tenant, and whether the controls can be reused elsewhere. Other information: damaged equipment with storage media may need a risk assessment to decide between destruction and repair or discard; careless disposal or reuse compromises information; full-disk encryption reduces disclosure risk if it covers the whole disk including slack space and swap, uses keys long enough to resist brute force, and keeps the keys confidential and off the same disk (8.24); overwriting techniques depend on the media technology and classification, so tools should be checked for suitability; ISO/IEC 27040 covers media sanitization methods.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 61 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ISM-0311 Sanitising media within IT equipment
  • ISM-0312 Returning overseas AUSTEO and AGAO equipment
  • ISM-0313 IT equipment sanitisation processes and procedures
  • ISM-0357 Sanitising EPROM media
  • ISM-0373 Supervisor duties and destruction certificates
  • ISM-0702 Cryptographic zeroise in emergency sanitisation
  • ISM-0840 NAID AAA certified destruction services
  • ISM-1223 Sanitising memory in network devices
  • ISM-1517 Destroying microfiche and microfilm
  • ISM-1550 IT equipment disposal processes and procedures
  • ISM-1728 Handling SECRET media waste particles
  • ISM-1729 Handling TOP SECRET media waste particles
  • ISM-1742 Destroying unsanitisable IT equipment

FedRAMP High · 3 controls

  • MA-3(3) Maintenance Tools | Prevent Unauthorized Removal (MA-3(3))
  • MP-6 Media Sanitization
  • SR-12 Component Disposal (SR-12)

FedRAMP Moderate · 3 controls

  • MA-3(3) Maintenance Tools | Prevent Unauthorized Removal (MA-3(3))
  • MP-6 Media Sanitization
  • SR-12 Component Disposal (SR-12)
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk

NIST SP 800-53 Rev 5 · 3 controls

SOC 2 · 3 controls

  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-P4.3 P4.3 Securely disposing of personal information

C5 (Germany) · 2 controls

CMMC 2.0 · 2 controls

HIPAA Security Rule · 2 controls

ISO 27701:2019 · 2 controls

  • 7.4.5 PII de-identification and deletion at the end of processing
  • 7.4.8 Disposal

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • 12.1.36.C.01 12.1.36.C.01 Leasing agreements address maintenance and sanitisation
  • 13.1.11.C.01 13.1.11.C.01 Contents of the system decommissioning plan

PCI DSS 4.0 · 2 controls

  • 9.4.6 9.4.6 Destruction of hard-copy materials
  • 9.4.7 9.4.7 Destruction of electronic media
  • E8-BACKUP-ML3 Regular Backups (ML3)
  • AUCDR-IS-3 Securely manage information assets over their lifecycle
  • AM-3 Ensure security of asset lifecycle management

CIS Controls v8 · 1 control

  • SD134-11 Secure Disposal

ISO 22301:2019 · 1 control

  • 8.3.4 Resource requirements

ISO 27001:2022 · 1 control

  • 7.14 Secure disposal or re-use of equipment

ISO 27018:2019 · 1 control

  • 11.2.7 Secure disposal or re-use of equipment

MTCS (Singapore) · 1 control

  • 12.9 Secure disposal and decommissioning of hardcopy, media and equipment

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

NIST SP 800-172 · 1 control

  • 3.14.5e Review Persistent Storage and Remove CUI No Longer Needed

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Physical controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 7.14 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 61 it maps to, and the evidence behind each claim, over MCP and REST.