Media handling and disposal policy
How storage media and equipment are used, moved, wiped and destroyed, and the record of destruction.
How the register reads it
| Also called | removable media policy, secure disposal, data destruction |
|---|---|
| Family | Assets, data and classification |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Folds into | The regimes accept it folded into the asset management policy; when neither is listed, the gap is counted once, under the parent. |
| Expected owner | The head of IT operations. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 27001 is ticked and no line resolves to it or to its parent (ISO 27701 requires it too, inside a parent document, so it does not list it separately). |
| Template | Media handling and disposal policy. |
Which standards require it, and what each expects it to contain
6 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27001:2022
ISO 27001 7.10 Storage mediaManage storage media across acquisition, use, transport and disposal per classification and handling rules.
What the ISO 27002 guidance expects the document to say: Requires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older source material adds that disposal should follow formal procedures scaled to the sensitivity of the information held, and that media in transit needs protection against unauthorised access, misuse and corruption.
Common gap: No documented classification for media
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.14 Secure disposal or re-use of equipmentVerify that sensitive data and licensed software are removed or securely overwritten before disposal or re-use.
What the ISO 27002 guidance expects the document to say: Requires items of equipment containing storage media to be verified before disposal or re-use, confirming that sensitive data and licensed software have been removed or securely overwritten.
Common gap: Relying on visual inspection only
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.10 Information deletionDelete information in systems, devices and media when no longer required.
What the ISO 27002 guidance expects the document to say: Requires information held in information systems, devices or any other storage media to be deleted once it is no longer required. Supporting material frames this as procedures for secure deletion at the point the information ceases to be needed.
Common gap: Retaining data beyond approved period
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO/IEC 27701:2025
ISO 27701 A.3.20 Storage mediaThe organization shall document any use of removable media or devices for the storage of PII and, wherever feasible, use media and devices that permit encryption, using unencrypted media only where unavoidable and then with procedures and compensating controls such as tamper-evident packaging to mitigate the risk, because media taken outside the organization is prone to loss, damage and inappropriate access; where media on which PII is stored is disposed of, secure disposal procedures shall be documented and implemented so that the previously stored PII is not accessible; and media carrying PII shall be handled under the transfer, logging and authorisation measures of A.3.7.
Common gap: Unencrypted USB media in routine use with no record
Source: ISO/IEC 27701:2025
ISO 27701 A.3.21 Secure disposal or re-use of equipmentWhenever storage space is re-assigned the organization shall ensure that any PII previously residing on it is not accessible, using specific technical measures where deletion of PII in an information system cannot practically be made explicit for performance reasons and another user could otherwise access it, and for disposal or re-use it shall treat equipment containing storage media that could possibly contain PII as though it does contain PII.
Common gap: Equipment resold or returned to lessors with storage intact
Source: ISO/IEC 27701:2025
ISO 27701 A.1.4.9 DisposalThe organization must hold documented policies, procedures or mechanisms for the disposal of personal data, choosing disposal techniques with regard to factors including the nature and extent of the data, any associated metadata, and the physical characteristics of the media it is stored on, since techniques differ in their properties and outcomes such as the granularity of the resulting media or whether deleted information can be recovered.
Common gap: One disposal method assumed adequate across all media, ignoring how outcomes differ
Source: ISO/IEC 27701:2025
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a register