← ISO 27001 · A.7 — Physical

A.7.10 — Storage media

medium media-disposalencryption-at-rest

Requirement

Storage media shall be managed through their life cycle of acquisition, use, transportation and disposal in accordance with the organisation's classification scheme and handling requirements.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
storage mediaremovable mediausbdisktape
Required element 2 — any one of
encryptdisposalhandlingprohibitedregisterdispose
Supporting terms — specificity signals
sanitis…sanitiz…destruction certificatetransportblocked

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
CCPA/CPRA 1798.100(e) & 1798.150 Reasonable security procedures encryption-at-rest
SOC 2 CC6.5 Disposal of physical and logical assets media-disposal
PCI DSS 4.0.1 3.5 PAN is rendered unreadable wherever it is stored encryption-at-rest
PCI DSS 4.0.1 9.4 Media with cardholder data is secured and destroyed media-disposal
HIPAA 164.310(d)(1) Device and media controls (R) media-disposal
HIPAA 164.312(a)(2)(iv) Encryption and decryption at rest (A) encryption-at-rest
GLBA 314.4(c)(3) Encryption of customer information in transit and at rest encryption-at-rest
NIST CSF 2.0 PR.DS-01 Confidentiality, integrity and availability of data at rest encryption-at-rest