SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.7.10Storage media

Manage the full lifecycle of storage media, from acquisition and use to secure disposal, to prevent unauthorized access, loss or leakage of the data on it.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Local admin and removable-media controls
The rules on who may have administrator rights on their own device and on the use of USB sticks and external drives.
Data retention and disposal procedure
The rules on how long data is kept and how it is securely destroyed when no longer needed.
From the Sekit evidence catalog

In practice

In practice storage media management splits into two everyday habits: blocking or restricting USB drives so data does not walk out the door, and destroying old hard drives and paper files with a method that leaves proof. Auditors ask for a destruction certificate from the last disposal batch and check whether it names the specific devices destroyed, then ask whether removable media is technically blocked or merely discouraged by policy. The common gap is a policy banning unapproved USB use that nobody enforces at the operating system level, so the rule depends entirely on staff choosing to follow it.

Common gaps

Removable media policy prohibits unapproved USB drives, but no technical control blocks them, so the rule depends on staff compliance alone.
Decommissioned laptops and drives sit in a storage closet for months awaiting destruction, with no chain-of-custody record while they wait.
The destruction certificate on file lists a batch count but not the individual device serial numbers, so it cannot prove which drive was destroyed.

Questions your auditor will ask

Are USB drives and removable media technically blocked, or only prohibited by policy?
Local admin and removable-media controls show the operating system blocking or restricting unapproved devices, not merely a written prohibition.
Can you prove a specific device was securely destroyed?
The data retention and disposal procedure produces a destruction certificate or wipe report naming the device, dated against when it left inventory.
How is media tracked between decommissioning and destruction?
Retired media is logged and tracked from decommissioning through destruction, with the gap kept short and the location known throughout.

Where regulation demands it

NIS2 12.5 requires the return or secure deletion of assets, the exact destruction discipline A.7.10 requires for storage media at end of life.
ENS mp.si.5 covers Borrado y destrucción, the same secure-wipe and destruction requirement A.7.10 sets for media leaving company control.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.7.10?”
Also via MCP, free with account