A.7.10 Physical
Storage media
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (24)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- MP-4mostlycovers — A.7.10's focus on preventing unauthorized disclosure/modification/removal/destruction of information on media directly accounts for the bulk of MP-4's secure storage and protection requirements, but leaves a residual on MP-4's physical-control and approved-destruction/sanitization procedures that sit outside A.7.10's explicit scope.
- MP-6mostlyaligns with — Both controls require organizations to sanitize or destroy storage media containing sensitive information before reuse or final disposal to prevent unauthorized disclosure.
- MP-6mostlycovers — A.7.10's requirement to protect storage media against unauthorized disclosure/modification/removal/destruction (including through sanitization before release/reuse) accounts for the bulk of MP-6's sanitization mandate and strength requirements, but leaves a residual on explicit procedural steps for different media types and formal tracking of sanitization actions that 27002 places in A.7.11 instead.
- MP-7mostlyaligns with — Both controls establish rules and procedures governing the acceptable use, handling, and protection of removable and portable storage media throughout their lifecycle.
- AC-3partialaligns with — Both controls enforce access restrictions on storage media by requiring authorization for removal and controlling who can access or handle the media.
- AU-2partialaligns with — Both controls mandate logging of key events such as media removal and disposal to maintain an auditable record of sensitive-asset handling.
- MP-4partialaligns with — Both controls address the secure physical storage of media, including protection against environmental threats and unauthorized access based on information sensitivity.
- MP-5partialaligns with — Both controls require security measures and accountability when media are physically transported outside organizational boundaries.
- MP-7partialcovers — A.7.10's focus on protecting storage media against unauthorized disclosure/modification/removal/destruction addresses only a slice of mp-7's broader requirements to restrict/limit/prohibit media use (including by type, on systems, and with no identifiable owner); most of mp-7 sits outside A.7.10.
- AC-3covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- MP-5covers — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (24)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-08mostlyaligns with — The control’s lifecycle-oriented procedures for authorizing, tracking, reusing, and disposing of storage media align with the CSF outcome of managing hardware, software, services, and data throughout their entire life cycles.
- PR.DS-01mostlyaligns with — By mandating encryption, secure storage, and environmental protection for media holding sensitive data, the ISO control fulfills the CSF goal of safeguarding the confidentiality, integrity, and availability of data at rest.
- PR.DS-11mostlyaligns with — The ISO control’s requirements for protecting, copying, and securely disposing of removable media directly support the CSF outcome of creating, protecting, maintaining, and testing backups to preserve data availability and integrity.
- GV.SC-07partialaligns with — Selecting vetted external disposal or collection services and logging their activities helps satisfy the CSF outcome of understanding, recording, and prioritizing risks introduced by third-party suppliers.
- PR.IR-02partialaligns with — Requiring storage of media in environments protected against heat, moisture, and other physical threats supports the CSF outcome of shielding technology assets from environmental hazards.
- PR.PS-01partialaligns with — Establishing topic-specific policies, authorization rules, and port-control measures for removable media contributes to the CSF outcome of applying configuration-management practices across the organization’s technology platforms.
- GV.SC-07implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.AM-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.DS-01implements — A.7.10 operationalizes protection of data-at-rest (via media handling that directly serves confidentiality and integrity) within the PR.DS domain, but the outcome does not name media controls specifically
- PR.DS-11implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-02implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (4)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (10)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-312nonemitigates — Mandating encryption for removable media and secure wiping before reuse prevents sensitive information from remaining in cleartext on portable storage that could later be lost or stolen.
- CWE-922nonemitigates — Secure reuse and disposal procedures, including cryptographic wiping and physical destruction, stop the insecure storage of sensitive data on media that may later be accessed by unauthorized actors.
- CWE-1263mitigates — Storage-media controls mitigate loss after physical access has occurred.
- CWE-200prevents — Requiring cryptographic protection, secure deletion, and controlled disposal of removable media directly reduces the chance that residual data on discarded or reused media can be recovered by an unauthorized party.
- CWE-530mitigates — Storage-media controls govern where and how backups are physically or logically stored, directly mitigating exposure.
- CWE-552mitigates — Authorizing and logging the removal of storage media, disabling unused ports, and monitoring transfers limit the exposure of files or directories to external parties outside the organization’s controlled environment.
- CWE-921mitigates — Storage-media controls mandate physical and logical protection of media holding sensitive information.
Mitigated MITRE ATT&CK techniques (184)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1003.003detects — A.7.10 requires monitoring the transfer of information to removable storage media and logging disposal of sensitive items, which can surface attempts to copy or exfiltrate NTDS.dit (or its backups) to removable media or during disposal/transport, but does not broadly detect the technique's other methods such as Volume Shadow Copy, ntdsutil.exe, or secretsdump.py on a live domain controller.
- T1011.001detects — A.7.10 requires monitoring transfers of information to removable storage media (including where ports like USB/Bluetooth adapters are enabled) and logging of sensitive media handling/disposal, which can surface anomalous exfiltration over Bluetooth in some implementations but is scoped only to authorized media use rather than broadly detecting the technique itself.
- T1020detects — A.7.10 requires monitoring transfers of information to removable storage media (and audit logging of removals/disposals), which can surface automated exfiltration that routes data onto such media, but this is only a slice of the technique's possible vectors (network C2, alternative protocols, non-removable destinations) and does not address detection once data has left the media.
- T1025detects — A.7.10 requires monitoring transfers of information TO removable media (and audit logging of removals/disposals), which can surface the post-compromise collection activity described in T1025 but only for the subset of cases that involve an actual transfer off the media rather than local search/copy.
- T1025prevents — A.7.10's policy, authorization, port-disable, monitoring, and cryptographic measures for removable media constrain the adversary's ability to freely search and collect from them on a compromised host, but do not stop the technique when media is already attached and the adversary has execution.
- T1048.003detects — A.7.10 requires monitoring transfers of information to removable storage media and logging of disposal/removals, which can surface exfiltration events that use removable media as the vector; this is a genuine but minority slice of T1048.003 (most instances use network protocols such as HTTP/FTP/DNS directly from the host, which the control does not instrument).
- T1052prevents — Requiring authorization, logging, and port disabling for removable media directly limits an adversary's ability to physically exfiltrate data via USB or other external devices.
- T1052detects — A.7.10 explicitly requires monitoring transfers of information to removable storage media (item i) and logging of removals/disposals (items b, e), which surfaces the exfiltration technique when it uses monitored/registered media, but this is scoped only to what the organization chooses to enable/monitor rather than all physical-medium exfiltration.
- T1052.001detects — A.7.10 explicitly requires monitoring the transfer of information to removable storage media (item i) and logging of removals/disposals (items b, e), which surfaces exfiltration activity over USB; this is only a slice of the full technique because the control's monitoring is scoped to organizational policy and removable-media handling rather than comprehensive detection of all USB exfiltration behaviors or hops.
- T1052.001prevents — A.7.10's policy, port-disable, monitoring, and secure-disposal rules can stop USB exfiltration in many cases (especially air-gapped or policy-enforced environments), but the control is governance-plus-selective-mechanism and does not universally block all USB data copy paths.
- T1074detects — A.7.10 requires monitoring the transfer of information to removable storage media (item i) and logging of disposals, which can surface staging activity when it touches monitored media or ports, but the control is silent on detecting staging that stays on fixed/internal/cloud storage or uses only in-memory/copy commands.
- T1074.001detects — A.7.10 requires monitoring transfers of information to removable storage media and logging of disposals/removals, which can surface local staging activity when it touches monitored media or ports, but the control is silent on detecting staging that stays entirely within local files, directories, the registry, or non-removable storage.
- T1080detects — A.7.10 requires monitoring transfers to removable media and logging of disposal/audit trails, which can surface anomalous tainting activity on monitored shared/removable storage but does not broadly instrument or detect binary infections, directory-share pivots, or tainted content already present on network drives/code repositories.
- T1091detects — A.7.10 requires monitoring transfers to removable media and logging of removals/disposals, which can surface anomalous or unauthorized use consistent with malware staging on media, but does not require detection of the malware itself, Autorun abuse, firmware modification, or the replication technique once underway.
- T1091prevents — A.7.10's policy, authorization, port-disable, monitoring, crypto, and secure-disposal guidance stop many vectors for malware placement or autorun on removable media, but leave open user-trickery (renamed legitimate-looking files), firmware manipulation, mobile-device infection paths, and cases where media is already malicious before organizational controls apply.
- T1092detects — A.7.10 explicitly requires monitoring transfers of information to removable media (item i) and logging of removals/disposals (items b, e), which surfaces the use of removable media for C2 command relay; this is genuine but only a slice because the control's scope is limited to authorized/registered media and does not mandate broad behavioral detection of the technique itself.
- T1092prevents — A.7.10's policy, authorization, port-disable, monitoring, crypto, and secure-disposal rules directly stop many removable-media C2 vectors (especially on air-gapped hosts), but the control is silent on the initial compromise of the Internet-facing system and on the T1091 replication step that seeds the media, leaving a genuine minority slice unaddressed.
- T1137.001prevents — A.7.10's policy, authorization, monitoring of transfers to removable media, port-disablement, and secure disposal guidance constrain some vectors for introducing or persisting malicious Office templates on removable or shared media, but do not address the dominant local file/registry/search-order abuse paths on a compromised endpoint.
- T1485recovers — A.7.10's secure reuse/disposal procedures (secure delete, shredding, cryptographic protection, media transfer before degradation, multiple copies) plus risk assessment on damaged devices enable recovery of availability for some destroyed or at-risk data, but do not address adversary-performed overwrites, cloud object/VM deletions, or worm-like propagation that renders data irrecoverable.
- T1486recovers — A.7.10 explicitly requires backup/transfer of information to fresh media, multiple separate copies, and secure disposal/reuse procedures that preserve availability of needed data after encryption events, matching the recovers verb; mostly because the control is scoped to managed removable/physical media and does not address in-place encryption of fixed disks, VMs, or cloud objects.
- T1552prevents — A.7.10's policy, authorization, crypto, port-disable, monitoring, and secure-delete guidance stop many classes of unsecured credential storage on removable and managed media, but leave the bulk of the technique (registry, shell history, app repos, private keys on fixed disks) untouched.
- T1552.001prevents — A.7.10's cryptographic protection (d), secure deletion/formatting before reuse or disposal (secure-reuse section), and port-control/monitoring rules reduce the chance that credentials will be left on removable or decommissioned media in recoverable form, but the control does not govern credential storage inside live files, configuration, source code, logs, backups, or VMs on persistent system storage.
- T1552.004prevents — A.7.10's guidance on cryptographic protection of removable media, secure deletion before reuse/disposal, port disabling, monitoring of transfers, and physical safeguards prevents the technique for keys stored on or transferred via removable media (including paper), but leaves the dominant case of keys stored directly on compromised system drives or in memory untouched.
- T1558.005prevents — A.7.10's policy, authorization, monitoring, port-disable, crypto-protection and secure-disposal rules for removable/storage media directly constrain on-disk ccache theft on Linux while leaving in-memory macOS ccache, /tmp defaults, and non-removable credential-cache scenarios untouched.
- T1561recovers — A.7.10 explicitly requires backup/transfer of information to fresh media before degradation, multiple separate copies of valuable data, and secure disposal/reuse procedures that preserve availability, directly enabling recovery from a disk-wipe event that has already destroyed on-system data.
- T1561.001detects — A.7.10 requires monitoring transfer of information to removable media and logging of disposal, which can surface anomalous wipe-like activity on removable or transportable media but does not address direct low-level disk wipes on fixed storage or network-wide propagation.
- T1561.001recovers — A.7.10 explicitly requires transferring information to fresh media before degradation, storing multiple backup copies on separate media, and secure disposal/reuse procedures that preserve availability of needed data, which directly enables recovery from a disk-wipe event; extent is partial because it addresses only the data layer (not full system restoration or non-media platforms) and recovery depends on prior copies existing outside the wiped target.
- T1561.002recovers — A.7.10 explicitly requires backup/transfer of information to fresh media before degradation and multiple copies on separate media to reduce loss, directly enabling recovery of the wiped structures and data after a T1561.002 event.
- T1565.001prevents — A.7.10's cryptographic protection, secure deletion/formatting, physical safeguards, and port/disablement rules stop many classes of at-rest manipulation on removable and physical media, but leave the bulk of stored-data manipulation (databases, Office files on fixed disks, custom formats inside running systems) untouched.
- T1567.001detects — A.7.10 requires monitoring transfers of information to removable storage media and logging of disposals, which can surface anomalous exfiltration to a code repo when it uses removable media or triggers disposal/transfer logging, but the control's scope is limited to physical/removable media and does not broadly instrument network API calls to code repositories.
- T1567.002detects — A.7.10 requires monitoring transfers of information to removable storage media (and registration/audit of removals), which can surface exfiltration to cloud storage clients when those act like attached media, but the control's scope is physical/removable media and its secure disposal procedures, leaving most network-based cloud exfil (e.g. direct API uploads) outside its view.
Prevented OWASP Web Top 10 (2025) risks (2)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A04mitigates — A.7.10's cryptographic techniques on removable media and secure disposal procedures bound the realized impact of weak/misused cryptography on that media (reducing leakage), but do not address the dominant at-rest/transit cases, web apps, keys, algorithms, or in-band failures that define A04.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.