A.7.10 Physical
Storage media
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (14)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- MP-6mostlyaligns with — Both controls require organizations to sanitize or destroy storage media containing sensitive information before reuse or final disposal to prevent unauthorized disclosure.
- MP-7mostlyaligns with — Both controls establish rules and procedures governing the acceptable use, handling, and protection of removable and portable storage media throughout their lifecycle.
- AC-3partialaligns with — Both controls enforce access restrictions on storage media by requiring authorization for removal and controlling who can access or handle the media.
- AU-2partialaligns with — Both controls mandate logging of key events such as media removal and disposal to maintain an auditable record of sensitive-asset handling.
- MP-4partialaligns with — Both controls address the secure physical storage of media, including protection against environmental threats and unauthorized access based on information sensitivity.
- MP-5partialaligns with — Both controls require security measures and accountability when media are physically transported outside organizational boundaries.
Aligned NIST CSF 2.0 outcomes (14)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-08mostlyaligns with — The control’s lifecycle-oriented procedures for authorizing, tracking, reusing, and disposing of storage media align with the CSF outcome of managing hardware, software, services, and data throughout their entire life cycles.
- PR.DS-01mostlyaligns with — By mandating encryption, secure storage, and environmental protection for media holding sensitive data, the ISO control fulfills the CSF goal of safeguarding the confidentiality, integrity, and availability of data at rest.
- PR.DS-11mostlyaligns with — The ISO control’s requirements for protecting, copying, and securely disposing of removable media directly support the CSF outcome of creating, protecting, maintaining, and testing backups to preserve data availability and integrity.
- GV.SC-07partialaligns with — Selecting vetted external disposal or collection services and logging their activities helps satisfy the CSF outcome of understanding, recording, and prioritizing risks introduced by third-party suppliers.
- PR.IR-02partialaligns with — Requiring storage of media in environments protected against heat, moisture, and other physical threats supports the CSF outcome of shielding technology assets from environmental hazards.
- PR.PS-01partialaligns with — Establishing topic-specific policies, authorization rules, and port-control measures for removable media contributes to the CSF outcome of applying configuration-management practices across the organization’s technology platforms.
Related OWASP ASVS 5.0 requirements (4)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (12)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263partialmitigates — Storage-media controls mitigate loss after physical access has occurred.
- CWE-200partialprevents — Requiring cryptographic protection, secure deletion, and controlled disposal of removable media directly reduces the chance that residual data on discarded or reused media can be recovered by an unauthorized party.
- CWE-530partialmitigates — Storage-media controls govern where and how backups are physically or logically stored, directly mitigating exposure.
- CWE-552partialmitigates — Authorizing and logging the removal of storage media, disabling unused ports, and monitoring transfers limit the exposure of files or directories to external parties outside the organization’s controlled environment.
- CWE-921partialmitigates — Storage-media controls mandate physical and logical protection of media holding sensitive information.
- CWE-312nonemitigates — Mandating encryption for removable media and secure wiping before reuse prevents sensitive information from remaining in cleartext on portable storage that could later be lost or stolen.
- CWE-528nonenone — Rules for protecting storage media apply to core-dump files, yet the control is not specific to crash-dump exposure.
- CWE-538nonenone — Logging disposals, selecting vetted external disposal services, and protecting media according to classification reduce the likelihood that sensitive information ends up in externally accessible files or directories.
- CWE-922nonemitigates — Secure reuse and disposal procedures, including cryptographic wiping and physical destruction, stop the insecure storage of sensitive data on media that may later be accessed by unauthorized actors.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1052mostlyprevents — Requiring authorization, logging, and port disabling for removable media directly limits an adversary's ability to physically exfiltrate data via USB or other external devices.
- T1005partialmitigates — Secure handling, encryption, and port restrictions make it harder for an adversary to copy sensitive files from the local system onto removable storage.
- T1025partialmitigates — Authorization, monitoring, and port controls reduce the opportunity for an attacker to collect data onto removable media without detection.
- T1070.004nonemitigates — Mandatory logging of media removal and disposal creates an audit trail that can reveal attempts to erase evidence of data theft.
- T1552.001nonemitigates — Secure disposal and reuse procedures reduce the chance that credentials or secrets stored on discarded media can be recovered by an attacker.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A02partialprevents — Mandating secure deletion, formatting, and controlled disposal procedures prevents residual data from remaining on media that is later reused or discarded, eliminating a common source of misconfiguration-related exposure.
- A04partialprevents — Requiring cryptographic protection on removable media directly reduces the chance that lost or stolen media will expose sensitive data in plaintext.
- A08nonemitigates — Logging disposals, maintaining audit trails for removals, and requiring authorization for media handling reduce the likelihood that data integrity will be compromised through unauthorized or untracked physical transfers.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.