A.7.14 Physical
Secure disposal or re-use of equipment
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (9)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- MP-6mostlycovers — Both controls require sanitization or physical destruction of storage media so that confidential information cannot be recovered before equipment is disposed of or reused.
- CM-2partialaligns with — Both controls require verification that security-relevant attributes and configurations are removed or reset before equipment leaves organizational custody.
- MP-7partialaligns with — Both controls restrict how media and equipment may be reused or transferred outside organizational control to prevent unauthorized disclosure of sensitive information.
- CM-2covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- MP-7covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (16)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-08mostlyaligns with — By requiring verification of storage media, removal of labels, and secure handling at end-of-life or lease termination, the control enforces lifecycle management of hardware and data assets.
- PR.DS-01mostlyaligns with — The ISO control ensures that data on storage media is rendered non-retrievable before equipment leaves organizational control, directly supporting protection of data-at-rest confidentiality and integrity during asset disposition.
- PR.PS-03mostlyaligns with — The control mandates secure removal or destruction of hardware and associated security mechanisms when equipment is disposed or returned, aligning with risk-commensurate hardware lifecycle practices.
- ID.RA-07partialaligns with — The control treats equipment disposal and lease-end scenarios as changes that must be assessed and managed to avoid residual information exposure risks.
- PR.IR-01partialaligns with — Removing organizational labels, access controls, and surveillance equipment at disposal prevents unauthorized parties from gaining residual logical or physical access to former assets.
- ID.AM-08implements — A.7.14 gives operational effect to the full life-cycle management outcome in ID.AM-08 by handling the end-of-life phase (secure disposal/re-use) that the CSF subcategory explicitly includes
- ID.RA-07implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.DS-01implements — A.7.14 gives operational effect to protecting data-at-rest confidentiality by ensuring information cannot leak from equipment that is disposed or reused, which sits inside the PR.DS-01 domain without the outcome explicitly naming disposal/re-use procedures.
- PR.IR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-03implements — A.7.14 gives operational effect to the hardware-removal and risk-commensurate disposal portion of PR.PS-03 by directly addressing secure sanitization to prevent information leakage when equipment is removed or replaced
Related OWASP ASVS 5.0 requirements (1)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (9)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-538noneprevents — Verifying and sanitizing equipment prior to disposal or resale prevents sensitive files or directories from remaining accessible to external parties who later obtain the hardware.
- CWE-922noneprevents — Mandating secure disposal techniques stops the insecure retention of sensitive information on storage media that leaves organizational control.
- CWE-1263prevents — Secure disposal prevents data exposure after equipment leaves controlled areas.
- CWE-1301prevents — Directly requires secure disposal or re-use of equipment to ensure data is completely removed.
- CWE-200prevents — Physically destroying or securely overwriting storage media before disposal or reuse directly prevents residual confidential data from remaining accessible to subsequent users or attackers.
- CWE-226prevents — Mandates secure disposal or re-use of equipment, covering media sanitization but not in-memory reuse.
- CWE-312mitigates — Requiring non-standard deletion or physical destruction of media ensures that sensitive information is not left in cleartext on discarded or repurposed equipment.
Mitigated MITRE ATT&CK techniques (36)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1052prevents — A.7.14's secure erasure, physical destruction and label-removal steps stop data on decommissioned or re-used equipment from being readable when that equipment itself is the exfiltration vector, but do not address adversary-introduced removable media used to carry data out of an already-compromised environment.
- T1486recovers — A.7.14 explicitly requires secure deletion/overwriting of information on storage media (and removal of labels) prior to disposal/re-use of equipment, directly enabling recovery of availability for data that would otherwise remain encrypted/inaccessible after a T1486 event on that media.
- T1552prevents — Overwriting or destroying storage media eliminates residual credentials left in files, registry hives, or configuration stores that an adversary could harvest after equipment is decommissioned.
- T1552.001prevents — A.7.14's secure deletion/overwriting of storage media and removal of labels before disposal or re-use directly stops credentials left in files on decommissioned equipment from being retrieved by an adversary searching for them, but this is only a minority slice of the technique which primarily targets live files, configs, logs, backups, and running systems across all platforms.
- T1552.004prevents — secure disposal and media sanitization before equipment re-use or resale directly stops private keys left on storage from being discoverable by an adversary who later acquires the device, but the control is silent on keys already present on live/compromised systems, on keys in memory or non-media locations, and on export via CLI while the system is still operational
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.