Storage media is small, portable, and easy to forget.
That is exactly why it represents one of the highest physical data loss risks.
Annex A 7.10 exists to ensure organisations protect information stored on storage media throughout its entire lifecycle, from acquisition and use through to reuse, transfer, and disposal.
This control is about preventing silent data loss and uncontrolled disclosure.

Annex A 7.10 of ISO 27001:2022 focuses on secure management of storage media.
At a practical level, this means:
The control applies to both digital and physical media, including removable media, fixed disks, backups, and paper records.
Storage media frequently contributes to serious incidents because it is:
Common risks include:
Annex A 7.10 ensures organisations do not treat storage media as a convenience tool, but as a controlled information asset.
The 2022 version consolidates multiple legacy controls into a single, lifecycle-focused control.
A pragmatic approach to Annex A 7.10 typically includes the following elements.
Organisations should define rules covering:
A topic-specific policy for removable media is explicitly expected in ISO 27001:2022.
Removable media introduces the highest risk.
Organisations typically consider:
Uncontrolled removable media use is a common audit and incident finding.
Storage media should be protected in line with the sensitivity of the information it holds.
This may include:
Protection should follow the data, not the device type.
Storage media can introduce malicious code.
Controls may include:
Storage media should not bypass other security controls.
Storage media degrades over time.
Organisations should consider:
Data loss due to media degradation is still common.
When storage media or physical documents are transferred:
Physical transfer is often underestimated compared to electronic transfer.
Before reuse within the organisation:
Reuse without sanitisation is a frequent source of accidental disclosure.
When storage media is no longer required:
Combining multiple disposed media can increase cumulative risk.
If external disposal services are used:
Disposal failures often occur outside organisational control.
Damaged media may still contain recoverable information.
Organisations should assess:
Physical damage does not guarantee data loss.
Annex A 7.10 does not require:
It does require organisations to:
Media-related incidents are usually quiet — and discovered too late.
Storage media failures rarely involve attackers — just oversight.
Annex A 7.10 is about controlling information in its most portable form.
When storage media is managed effectively:
Data does not disappear when systems change.
Annex A 7.10 ensures it is controlled until the very end.
We can help you understand your actual security needs and even if we cant help we can point you in the right direction
Talk to a security expert today