Where IT Disposal Fits in ISO 27001

ISO 27001 is the international standard for information security management systems (ISMS), and it’s increasingly common among Australian businesses, particularly those in technology, finance, healthcare, and government contracting. IT asset disposal is explicitly addressed within ISO 27001’s control framework, and getting it wrong can jeopardise your certification.

For organisations pursuing or maintaining ISO 27001 certification, understanding the specific controls that relate to equipment disposal is essential. The standard takes a risk-based approach, meaning your disposal processes need to be proportionate to the sensitivity of the data involved.

The Relevant Controls

ISO 27001:2022 includes several controls directly related to IT asset disposal. The most important are found in Annex A, which provides the control set that organisations must consider:

A.7.14 – Secure disposal or re-use of equipment: This is the primary control. It requires that all items of equipment containing storage media must be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use. This control applies to all equipment, not just computers and servers, including printers, phones, network equipment, and any other device with storage capability.

A.7.10 – Storage media: This control addresses the management of storage media throughout its lifecycle, including disposal. It requires that media containing confidential information be disposed of securely, for example by incineration, shredding, or data erasure to a level that the original information cannot be retrieved.

A.5.9 – Inventory of information and other associated assets: You can’t dispose of assets properly if you don’t know what you have. This control requires maintaining an inventory of assets, which directly supports disposal processes by ensuring no devices fall through the cracks.

A.5.10 – Acceptable use of information and other associated assets: This covers how assets should be handled, including during the decommissioning phase.

Key ISO 27001 controls for IT disposal:

  • A.7.14 – Secure disposal or re-use of equipment
  • A.7.10 – Storage media lifecycle management
  • A.5.9 – Asset inventory (know what needs disposing)
  • A.5.10 – Acceptable use including decommissioning rules
  • A.5.37 – Documented operating procedures (for disposal processes)
  • A.8.10 – Information deletion (data lifecycle management)

What Auditors Look For

During an ISO 27001 certification or surveillance audit, auditors examine whether your disposal practices match your documented policies and whether those policies adequately address the risks. Specific areas they’ll probe include:

Policy documentation: Is there a documented policy for secure equipment disposal? Does it cover all device types? Is it reviewed regularly? Does it specify approved destruction methods?

Asset tracking: Can you trace an asset from procurement through to verified disposal? Are there gaps in the chain of custody? Is there a record of every device that’s been disposed of?

Destruction evidence: Do you have certificates of destruction? Do they include serial numbers matching your asset register? Are they signed by authorised personnel or providers?

Risk assessment: Have you assessed the risks associated with your disposal process? Is the destruction method proportionate to the classification of the data?

Supplier management: If you use third-party disposal providers, have they been assessed and approved? Are there contractual requirements for data destruction? Do you verify their performance?

Staff awareness: Do people involved in equipment disposal understand their responsibilities? Have they received appropriate training?

Risk-Based Approach to Destruction Methods

ISO 27001 is built on risk assessment, and the standard expects your destruction methods to be proportionate to the risk level of the data involved. This doesn’t mean every device needs the same treatment.

For devices that held classified, highly sensitive, or regulated data (financial records, health data, legal privilege material), physical destruction or multi-pass overwriting with verification is typically appropriate. The risk of data recovery is high, and the consequences of a breach are severe.

For devices that held general business data with lower sensitivity, software-based wiping to standards like NIST 800-88 is usually adequate. The destruction method should still render data unrecoverable, but the approach can be less extreme than for highly classified material.

For devices with no data (brand new, never deployed, or used for non-data purposes), simple asset deregistration and standard recycling may be sufficient, though it’s good practice to wipe them anyway as a precaution.

Your risk assessment should be documented and reviewed periodically. If you can’t articulate why you chose a particular destruction method for a given data classification, an auditor will flag it.

Documentation Requirements

ISO 27001 places heavy emphasis on documentation, and disposal is no exception. The documentation trail for each disposed asset should include:

The asset’s identity (serial number, asset tag, model, type). Its data classification and the nature of information it held. The date it was decommissioned and removed from service. Chain of custody records showing who handled it and when. The destruction method applied and the standard followed. Verification that destruction was successful. The certificate of destruction or equivalent documentation. The identity of the person or provider who performed the destruction.

This documentation needs to be retained in accordance with your records management policy. Most organisations retain disposal records for at least as long as their data retention schedule requires, often 7 years or more for compliance-sensitive data.

Third-Party Provider Requirements

Many organisations outsource IT disposal to specialist providers. Under ISO 27001, using a third party doesn’t remove your responsibility for the security of the data. The standard requires that you assess the provider’s capability before engaging them, include security requirements in the contract, monitor their performance, and maintain evidence of their destruction activities.

When selecting a provider, look for their own ISO 27001 certification (demonstrating they apply the same standard to their own operations), AS/NZS 5377 certification for e-waste handling, NIST 800-88 or ADISA-certified destruction processes, comprehensive insurance coverage, and willingness to allow audit access to their facilities.

Include specific requirements in your contract: destruction methods to be used, certificate format and content, turnaround times, secure transport arrangements, and the right to audit.

Common Non-Conformities

These are the disposal-related issues that most commonly result in audit findings:

Incomplete asset registers: Devices that were disposed of but never removed from the asset register, or devices that disappeared without any disposal record.

Missing destruction certificates: Disposal occurred but there’s no documented evidence. The auditor sees a gap between “device in service” and “device gone” with nothing in between.

No supplier assessment: Third-party disposal providers used without any documented assessment of their security capabilities or contractual security requirements.

Inconsistent application: The policy exists and is sometimes followed, but not consistently. Some departments follow the process while others dispose of equipment ad hoc.

Overlooked device types: The policy covers laptops and servers but ignores printers, phones, network equipment, or IoT devices that also contain data.

Audit-ready disposal checklist:

  • Documented disposal policy covering all device types
  • Risk assessment linking data classification to destruction methods
  • Complete asset register tracking devices through to disposal
  • Certificates of destruction with serial numbers for every asset
  • Supplier assessments and contracts with security requirements
  • Staff training records for disposal procedures
  • Periodic internal audits of the disposal process

Integrating Disposal Into Your ISMS

The key to meeting ISO 27001’s disposal requirements is treating equipment disposal as a core information security process, not an administrative afterthought. It should be included in your ISMS scope, covered by your risk assessment, addressed in your policies, and subject to the same continuous improvement cycle as every other security control.

Regular internal audits of the disposal process help catch issues before external auditors do. Include disposal in your management review agenda so senior leadership has visibility of how it’s performing. And update your processes as technology changes, because the methods that work for HDDs don’t necessarily work for SSDs, NVMe drives, or cloud infrastructure.

For more on the technical side of data destruction, see our guide to NIST 800-88 and our comparison of hard drive destruction methods.

EWV handles IT asset disposition (ITAD) end-to-end for Victorian businesses — from collection and data destruction through to certified recycling or refurbishment for resale. Get in touch for a tailored ITAD quote.