ISO 27001 Storage Media Explained – Control 7.10

ISO 27001 Storage Media Explained – Control 7.10

Storage media is small, portable, and remarkably easy to forget—which is precisely why it represents one of the highest physical data loss risks in any business. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations implement flawless cloud perimeters and firewalls, only to lose customer databases because an employee lost an unencrypted USB stick in a café, plugged a found flash drive into a server, or threw old backup tapes into an office recycling bin. Storage media is a controlled information asset, not a convenience tool.

ISO 27001:2022 includes Annex A 7.10 to ensure you protect information stored on physical and digital media throughout its entire lifecycle—from acquisition, daily handling, and transport, to secure wiping, re-use, and final destruction. This control consolidates several legacy 2013 requirements into a single, cohesive framework covering removable media, fixed drives, backup tapes, and physical paper records.

Quick Summary: What ISO 27001 Annex A 7.10 Requires

At a practical level, Annex A 7.10 is about controlling information in its most portable and vulnerable forms. It does not require banning all portable storage across your business, but it demands strict lifecycle governance and risk-proportionate protection. Here is what you need to do in plain English:

  • Publish a Removable Media Policy: Establish topic-specific rules governing the acquisition, usage, off-site transport, and disposal of storage media.
  • Enforce Mandatory Encryption: Encrypt all portable media (USB drives, external SSDs, backup tapes) containing confidential data (Annex A 8.24).
  • Restrict Unauthorised USB Access: Disable USB storage ports by default on endpoints, requiring explicit business justification and admin sign-off for exceptions.
  • Scan Media for Malware: Ensure all external media is automatically scanned for malicious code before files are accessed or transferred (Annex A 8.7).
  • Secure Media in Transit: Use trackable couriers and tamper-evident packaging when physically moving storage media or confidential paper archives off-site.
  • Sanitise or Destroy Before Disposal: Irreversibly wipe media before internal re-use or physically shred retired media before disposal (Annex A 7.14).

Why Storage Media Is a Major Physical Security Hazard

Storage media acts as a physical bridge between trusted corporate environments and untrusted external spaces. Because devices are small, easily misplaced, and simple to duplicate, uncontrolled media introduces severe risks of accidental disclosure, physical theft, and malware contamination.

Ignoring storage media security controls exposes your business to severe hazards:

  • Mass Breach via Lost Media: An employee losing an unencrypted USB drive or external hard drive containing unmasked customer records or HR files.
  • Malware Bridging & Air-Gap Bypasses: Infected removable media introducing ransomware, keyloggers, or malicious scripts directly into internal subnets.
  • Data Exposure During Re-Use: Reissuing an unformatted external drive to a new employee or department with legacy confidential files still intact.
  • Third-Party Disposal Failures: Discarding faulty or retired hard drives without verifiable proof of cryptographic erasure or physical destruction.

My 10 Step Plan to Implement Annex A 7.10 Fast

You do not need to overcomplicate your hardware inventory to satisfy an ISO 27001 auditor. Here is my pragmatic, 10-step plan to establish an audit-ready storage media management framework.

1. Publish a Topic-Specific Storage Media Policy

Document explicit rules governing how storage media is acquired, handled, stored, moved, and destroyed across its full lifecycle:

  • Define permitted media types (e.g., corporate-issued encrypted USBs, external SSDs, backup tapes, paper records).
  • Outline mandatory approval workflows for removing storage media carrying sensitive data off-premises.
  • Set clear user responsibilities for physical media storage when working remotely or travelling.

2. Restrict Removable Storage Ports by Default

Block unmanaged mass storage devices across corporate endpoints to prevent uncontrolled data copying (Annex A 8.12):

  • Disable USB mass storage write access globally via Endpoint Management (MDM / Group Policy) (Annex A 8.1).
  • Establish an exception process granting USB write access strictly to authorized roles with a verified business need.
  • Restrict USB access exclusively to corporate-approved, hardware-encrypted flash drives.

3. Enforce Mandatory Hardware and Software Encryption

Ensure that even if physical media is stolen or lost, the underlying data remains completely unreadable:

  • Enforce AES-256 encryption across all external hard drives, USB sticks, and portable backup media (Annex A 8.24).
  • Store master encryption recovery keys in a central, restricted key management vault.
  • Apply physical locks or secure cabinets to offline backup tape archives and sensitive paper files.

4. Automatically Scan Removable Media for Malware

Prevent portable storage devices from acting as physical vectors for malware infections (Annex A 8.7):

  • Configure Endpoint Detection and Response (EDR) agents to scan plugged-in removable media automatically before mounting.
  • Block autorun and autoplay capabilities across all operating systems.
  • Deploy isolated “Kiosk” stations for scanning external vendor or client USB drives before ingesting files into production networks.

5. Secure Storage Media in Transit

Protecting media during physical transportation between offices, datacenters, or off-site archives is critical:

  • Use trackable, vetted courier services providing chain-of-custody documentation for sensitive physical media moves.
  • Transport media inside locked, tamper-evident containers or padded protective cases to prevent physical damage.
  • Verify that data stored on transported media is encrypted at rest prior to transit.

6. Manage Media Degradation and Maintain Availability

Digital and physical storage media degrades over time, creating silent data corruption risks (Annex A 8.13):

  • Establish lifecycle refresh cycles for physical backup tapes, optical disks, and flash drives before bit-rot occurs.
  • Maintain redundant backup copies across geographically separated cloud or physical locations.
  • Inspect archived media periodically to verify readability and data integrity.

7. Securely Sanitise Media Before Internal Re-Use

Reissuing storage media between staff or business units without proper wiping creates a major accidental disclosure window:

  • Perform multi-pass secure overwriting or cryptographic erasure on storage media before reallocating it (Annex A 8.11).
  • Verify that logical partitions, system caches, and hidden recovery sectors are scrubbed completely.
  • Maintain a log recording the serial number, wiping method, date, and engineer sign-off for re-issued media.

8. Secure Physical and Digital Media Disposal

When storage media reaches its end of operational life, enforce permanent data destruction (Annex A 7.14):

  • Cryptographically erase self-encrypting drives by destroying master decryption keys (crypto-shredding).
  • Physically shred, degauss, or disintegrate retired media (hard drives, tapes, USBs) to render recovery impossible.
  • Store media awaiting destruction inside locked, tamper-evident disposal bins within secure zones (Annex A 7.10).

9. Audit Third-Party Disposal and Recycling Vendors

Outsourcing media destruction does not remove your ultimate ISO 27001 compliance liability:

  • Perform due diligence on third-party IT Asset Disposition (ITAD) vendors before contracting (Annex A 8.30).
  • Require vendors to provide formal, serialised Certificates of Destruction detailing drive serial numbers and destruction methods.
  • Ensure vendor transport vehicles use locked, GPS-monitored containers during pickup and transit.

10. Extend Storage Media Controls to Physical Paper Records

Annex A 7.10 explicitly includes physical paper records containing sensitive operational or customer data:

  • Store confidential paper archives inside locked filing cabinets or access-controlled archive rooms.
  • Enforce a strict Clean Desk Policy (Annex A 7.7) requiring staff to lock away paper files when unattended.
  • Provide secure cross-cut shredding bins for disposing of confidential paper documents.

Common Implementation Pitfalls and How to Fix Them

When preparing clients for ISO 27001 audits, I frequently spot the same storage media management mistakes. Here are the main traps and how to solve them:

  • Problem: Unrestricted USB Mass Storage Access Granted Across All Laptops
    Ninja Solution: Block USB write access globally using MDM policies, granting exceptions only for encrypted corporate drives.
  • Problem: Throwing Faulty or Retired Hard Drives into Standard E-Waste Bins
    Ninja Solution: Lock retired drives in a secure disposal container and obtain serialised Certificates of Destruction upon disposal.
  • Problem: Ignoring Paper Documents and Focus Only on Digital Storage Media
    Ninja Solution: Treat paper files carrying confidential data as physical storage media subject to clean desk policies and secure shredding.
  • Problem: Re-Issuing Laptops or External Drives Without Wiping Previous User Data
    Ninja Solution: Enforce a mandatory IT offboarding checklist that requires full drive wiping before hardware re-allocation.

The ISO 27001 Ninja Bottom Line

ISO 27001 Annex A 7.10 is about managing information in its most portable, vulnerable form throughout its entire lifecycle. Storage media failures rarely involve sophisticated external cyber attacks; they stem from oversight, unmanaged convenience, and poor disposal habits.

By publishing a clear removable media policy, enforcing full-disk encryption, locking down unapproved USB ports, scanning media for malware, securing physical transport, and obtaining proof of destruction, you eliminate portable data leakage risks, protect confidentiality, and satisfy your ISO 27001 auditor with complete confidence.