Skip to content
arrow_back
search
Annex A 7.14 verified ISO/IEC 27001:2022

Secure disposal or re-use of equipment

Ensure device data is erased or secured before disposal or reuse to prevent data breaches.

record_voice_over

Plain language

This control is about making sure that any device you want to throw away or give to someone else has all its data completely wiped clean. If you don't do this, someone could find your sensitive information and use it against you.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Physical controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Items of equipment containing storage media shall be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use.
verified ISO/IEC 27001:2022 Annex A 7.14
priority_high

Why it matters

Failing to securely erase devices can cause data breaches or licensing issues, exposing sensitive information to unauthorised parties.

settings

Operational notes

Train staff in secure disposal. Before re-use or disposal, verify data removal and use approved wiping or destruction methods; keep disposal logs and certificates from recyclers.

Mapping detail

Mapping

Direction

Controls