Policy Register

Media handling and disposal policy

How storage media and equipment are used, moved, wiped and destroyed, and the record of destruction.

How the register reads it

Also calledremovable media policy, secure disposal, data destruction
FamilyAssets, data and classification
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the asset management policy; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe head of IT operations.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 27001 is ticked and no line resolves to it or to its parent (ISO 27701 requires it too, inside a parent document, so it does not list it separately).
TemplateMedia handling and disposal policy.

Which standards require it, and what each expects it to contain

6 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 7.10 Storage media

Manage storage media across acquisition, use, transport and disposal per classification and handling rules.

What the ISO 27002 guidance expects the document to say: Requires storage media to be managed across their whole life cycle, covering acquisition, use, transportation and disposal, in accordance with the organisation's classification scheme and handling requirements. Older source material adds that disposal should follow formal procedures scaled to the sensitivity of the information held, and that media in transit needs protection against unauthorised access, misuse and corruption.

Evidence an auditor accepts: Procedures covering media across acquisition, use, transportation and disposal, tied to the classification scheme; the media register or tracking record for removable and archival media, showing location and content classification; evidence of protection in transit, including packaging, carrier selection and receipt confirmation
Common gap: No documented classification for media
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 7.14 Secure disposal or re-use of equipment

Verify that sensitive data and licensed software are removed or securely overwritten before disposal or re-use.

What the ISO 27002 guidance expects the document to say: Requires items of equipment containing storage media to be verified before disposal or re-use, confirming that sensitive data and licensed software have been removed or securely overwritten.

Evidence an auditor accepts: The procedure for disposal and re-use of equipment containing storage media, defining the sanitisation method per media type; verification records confirming sensitive data and licensed software were removed or securely overwritten, per item; asset register entries showing the transition from in use to sanitised to disposed or reissued
Common gap: Relying on visual inspection only
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022
ISO 27001 8.10 Information deletion

Delete information in systems, devices and media when no longer required.

What the ISO 27002 guidance expects the document to say: Requires information held in information systems, devices or any other storage media to be deleted once it is no longer required. Supporting material frames this as procedures for secure deletion at the point the information ceases to be needed.

Evidence an auditor accepts: Deletion rules tied to retention requirements, per information type and per system; evidence of deletion actually performed, such as job records, deletion logs or reports of records removed; the method used for each medium, and evidence it renders the information unrecoverable to the required standard
Common gap: Retaining data beyond approved period
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 27701:2025

ISO 27701 A.3.20 Storage media

The organization shall document any use of removable media or devices for the storage of PII and, wherever feasible, use media and devices that permit encryption, using unencrypted media only where unavoidable and then with procedures and compensating controls such as tamper-evident packaging to mitigate the risk, because media taken outside the organization is prone to loss, damage and inappropriate access; where media on which PII is stored is disposed of, secure disposal procedures shall be documented and implemented so that the previously stored PII is not accessible; and media carrying PII shall be handled under the transfer, logging and authorisation measures of A.3.7.

Evidence an auditor accepts: Register of removable media and devices used for PII; encryption applied to media holding PII, with documented exceptions and their compensating controls; secure disposal procedure and disposal records for media that held PII
Common gap: Unencrypted USB media in routine use with no record
Source: ISO/IEC 27701:2025
ISO 27701 A.3.21 Secure disposal or re-use of equipment

Whenever storage space is re-assigned the organization shall ensure that any PII previously residing on it is not accessible, using specific technical measures where deletion of PII in an information system cannot practically be made explicit for performance reasons and another user could otherwise access it, and for disposal or re-use it shall treat equipment containing storage media that could possibly contain PII as though it does contain PII.

Evidence an auditor accepts: Sanitisation procedure for equipment and storage before re-use or disposal; records of sanitisation or destruction per device; technical measures applied where explicit erasure is impractical, for example encryption with key destruction
Common gap: Equipment resold or returned to lessors with storage intact
Source: ISO/IEC 27701:2025
ISO 27701 A.1.4.9 Disposal

The organization must hold documented policies, procedures or mechanisms for the disposal of personal data, choosing disposal techniques with regard to factors including the nature and extent of the data, any associated metadata, and the physical characteristics of the media it is stored on, since techniques differ in their properties and outcomes such as the granularity of the resulting media or whether deleted information can be recovered.

Evidence an auditor accepts: Disposal policy naming the technique used per media type and data category; disposal records identifying what was disposed of, when, by whom and by what method; consideration of associated metadata in the disposal decision
Common gap: One disposal method assumed adequate across all media, ignoring how outcomes differ
Source: ISO/IEC 27701:2025

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Information transfer policy · Records retention schedule