A.7.14 Physical
Secure disposal or re-use of equipment
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (6)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- MP-6mostlycovers — Both controls require sanitization or physical destruction of storage media so that confidential information cannot be recovered before equipment is disposed of or reused.
- CM-2partialaligns with — Both controls require verification that security-relevant attributes and configurations are removed or reset before equipment leaves organizational custody.
- MP-7partialaligns with — Both controls restrict how media and equipment may be reused or transferred outside organizational control to prevent unauthorized disclosure of sensitive information.
Aligned NIST CSF 2.0 outcomes (9)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-08mostlyaligns with — By requiring verification of storage media, removal of labels, and secure handling at end-of-life or lease termination, the control enforces lifecycle management of hardware and data assets.
- PR.DS-01mostlyaligns with — The ISO control ensures that data on storage media is rendered non-retrievable before equipment leaves organizational control, directly supporting protection of data-at-rest confidentiality and integrity during asset disposition.
- PR.PS-03mostlyaligns with — The control mandates secure removal or destruction of hardware and associated security mechanisms when equipment is disposed or returned, aligning with risk-commensurate hardware lifecycle practices.
- ID.RA-07partialaligns with — The control treats equipment disposal and lease-end scenarios as changes that must be assessed and managed to avoid residual information exposure risks.
- PR.IR-01partialaligns with — Removing organizational labels, access controls, and surveillance equipment at disposal prevents unauthorized parties from gaining residual logical or physical access to former assets.
Related OWASP ASVS 5.0 requirements (1)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (10)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1263mostlyprevents — Secure disposal prevents data exposure after equipment leaves controlled areas.
- CWE-1301mostlyprevents — Directly requires secure disposal or re-use of equipment to ensure data is completely removed.
- CWE-226mostlyprevents — Mandates secure disposal or re-use of equipment, covering media sanitization but not in-memory reuse.
- CWE-200partialprevents — Physically destroying or securely overwriting storage media before disposal or reuse directly prevents residual confidential data from remaining accessible to subsequent users or attackers.
- CWE-312partialmitigates — Requiring non-standard deletion or physical destruction of media ensures that sensitive information is not left in cleartext on discarded or repurposed equipment.
- CWE-532nonenone — Secure erasure of storage media before disposal removes any log files or debug output that may contain sensitive operational details from the device.
- CWE-538noneprevents — Verifying and sanitizing equipment prior to disposal or resale prevents sensitive files or directories from remaining accessible to external parties who later obtain the hardware.
- CWE-922noneprevents — Mandating secure disposal techniques stops the insecure retention of sensitive information on storage media that leaves organizational control.
Mitigated MITRE ATT&CK techniques (5)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1005partialmitigates — Physically destroying or securely overwriting storage media prevents an adversary from retrieving files that were collected from the local system and later discarded with the hardware.
- T1552partialprevents — Overwriting or destroying storage media eliminates residual credentials left in files, registry hives, or configuration stores that an adversary could harvest after equipment is decommissioned.
- T1025nonemitigates — Ensuring removable media is wiped or destroyed before disposal stops an attacker from recovering staged data that was copied onto USB drives or other portable media.
- T1074nonemitigates — Secure disposal of media that holds locally or remotely staged data denies an attacker the opportunity to recover that staged information from disposed equipment.
- T1530nonemitigates — Destroying or sanitizing storage media that may contain cloud-stored data downloaded to endpoints prevents adversaries from retrieving that data from discarded devices.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.