Skip to content
Singahi

Compliance · guide

ISO 27001 A.7.10: Storage Media

48 min read

Share
On this page

Quick Reference (60 Seconds)

Figure · At a glance

A.7.10 at a glance

Control ID
A.7.10
Control Name
Storage Media
ISO 27002:2022 Section
7.10
Primary Purpose
Manage storage media throughout its
Key Activities
Inventory media, classify sensitivity
Typical Owners
IT Security, Data Protection Officer
The essentials before reading further. The full reference table follows.
AspectSummary
Control IDA.7.10
Control NameStorage Media
ISO 27002:2022 Section7.10
Primary PurposeManage storage media throughout its lifecycle to prevent unauthorized disclosure, modification, removal, or destruction
Key ActivitiesInventory media, classify sensitivity, secure storage, restrict access, track movement, dispose securely
Typical OwnersIT Security, Data Protection Officer, IT Operations
Implementation EffortMedium (4–6 weeks)
Annual overhead Range– for growing companies

Bottom Line: Storage media is the physical container of your information. Every USB drive, tape, disk, and printout is a potential breach waiting to happen if not managed properly. This control ensures media is tracked, protected, and disposed of securely.


What the Standard Actually Requires

Figure · Process

What A.7.10 asks you to do

The 7 requirements of ISO 27001 A.7.10, storage media, in order: media inventory and classification; secure storage; access restriction; movement and transfer; disposal and destruction; backup media management; audit and accountability.
The 7 things the control expects. Each is expanded in the section below.

ISO 27001:2022 Annex A.7.10 states:

ISO 27001:2022 Annex A 7.10 asks organizations to manage storage media through their life cycle of acquisition, use, transport, and disposal, in line with the classification scheme.

ISO 27002:2022 expands this into practical guidance covering:

  1. Media inventory and classification, Knowing what media exists and what it contains
  2. Secure storage, Protecting media from unauthorized access, environmental damage, and theft
  3. Access restriction, Limiting who can access, modify, or remove media
  4. Movement and transfer, Controlling how media is transported between locations
  5. Disposal and destruction, Ensuring media is securely destroyed when no longer needed
  6. Backup media management, Ensuring backup tapes and disks are properly stored and rotated
  7. Audit and accountability, Tracking all media-related activities

Why Storage Media Matters

The Forgotten Attack Vector

In the digital age, organizations focus heavily on network security, cloud security, and endpoint security. But storage media, the physical disks, tapes, USB drives, and printouts that contain information, is often overlooked. A single lost USB drive or improperly disposed hard disk can cause a breach as severe as any sophisticated cyberattack.

Key Statistics

  • 60% of organizations have experienced data loss from lost or stolen removable media
  • USB drives and laptops are the top two causes of data breaches involving physical devices
  • Improper disposal of hard drives is a leading cause of data recovery by malicious actors
  • Backup tapes are frequently lost in transit or stored insecurely, exposing entire organizational datasets
  • India’s DPDP Act 2023 imposes penalties up to for data breaches, including those from physical media

Real-World Consequences

  • Lost backup tape containing 1 million customer records was found in a taxi; the taxi driver sold the data to a competitor
  • Improperly wiped hard drives sold at auction contained recoverable financial records, leading to regulatory fines
  • USB drive left in a conference room contained merger plans, which were leaked to the press
  • Printed documents left in a recycling bin were photographed by a competitor's employee
  • Unencrypted backup tapes stored in an unlocked cabinet were stolen during a break-in, exposing all customer data

Regulatory and Business Drivers

  • DPDP Act 2023, Personal data must be protected on all media; breach notification required within 72 hours
  • IT Act 2000 (Section 43A), Compensation for failure to protect sensitive personal data
  • RBI Cyber Security Framework, Backup media must be encrypted and stored securely; off-site storage required
  • PCI DSS v4.0, Requirement 9.5 mandates physical security of media; Requirement 3.4 requires rendering PAN unreadable on all media
  • SOC 2 CC6.1, Logical and physical access controls must protect stored data

Scope and Applicability

What Is Covered

  • All physical storage media containing organizational information
  • Magnetic media (hard drives, tapes, floppy disks)
  • Optical media (CDs, DVDs, Blu-ray)
  • Flash media (USB drives, SSDs, memory cards, SD cards)
  • Printed documents and paper records
  • Microfilm and microfiche
  • Mobile devices with storage (smartphones, tablets, laptops)
  • Backup media of all types
  • Archive media and long-term storage

What Is Not Covered

  • Empty media not yet assigned to store information (though procurement should be controlled)
  • Media owned by employees and not used for work (though BYOD policies may extend coverage)

Applicability by Organization Type

Organization TypeApplicabilityKey Media Concerns
IT/Software ServicesHighSource code repositories, customer data, dev backups
BFSICriticalCustomer financial records, transaction logs, backup tapes
HealthcareCriticalPatient records, medical images, lab results
ManufacturingMediumR&D designs, production plans, supplier contracts
Government/DefenseCriticalClassified documents, citizen records, strategic plans
EducationMediumStudent records, exam materials, research data
SaaS/CloudHighCustomer tenant data, backup archives, log files
Legal/ConsultingHighClient confidential information, case files

Key Definitions and Terminology

TermDefinition
Storage MediaAny physical device or material capable of storing information, including magnetic, optical, flash, and paper media
Removable MediaStorage media that can be easily removed from a system, such as USB drives, external hard drives, CDs, and tapes
Media LifecycleThe stages a media item goes through from procurement to disposal: procurement → assignment → use → archival → disposal
Media SanitizationThe process of removing data from media so that it cannot be recovered, ranging from overwriting to physical destruction
DegaussingThe process of using a strong magnetic field to erase data from magnetic media (tapes, hard drives)
ShreddingPhysical destruction of media into small pieces, preventing data recovery
IncinerationBurning media to ash, ensuring complete destruction
Encryption at RestEncrypting data on media so that even if the media is stolen, the data cannot be read without the decryption key
Media VaultA secure, climate-controlled facility for storing backup and archive media
Off-Site StorageStoring backup media at a geographically separate location to protect against site-wide disasters
Rotation SchemeA scheduled plan for rotating backup media (e.g., daily, weekly, monthly) to ensure recoverability and retention
Media ClassificationAssigning a sensitivity label to media based on the data it contains, aligned with the information classification scheme

Relationship to Other Controls

ControlRelationship
A.5.9 Inventory of information and other assetsMedia inventory is part of the overall asset inventory
A.5.12 Classification of informationMedia must be classified according to the information it contains
A.5.33 Protection of recordsStorage media is the physical form of records
A.7.2 Physical entry controlsMedia storage areas must have controlled access
A.7.6 Working in secure areasMedia handling in secure areas requires additional controls
A.7.8 Equipment siting and protectionMedia storage environment must be environmentally controlled
A.7.10 Cabling securityMedia transfer may involve physical cables
A.7.13 Secure disposal of equipmentMedia disposal is a subset of equipment disposal
A.8.1 User endpoint devicesEndpoint devices contain media that must be managed
A.8.5 Secure authenticationAccess to media storage requires authentication
A.8.10 Information backupBackup media is a primary media management concern
A.8.11 Data maskingData masking reduces sensitivity of media contents
A.8.24 Use of cryptographyEncryption protects data on media if the media is lost or stolen
A.8.34 Protection of information systems during disruptionMedia protection during disasters and disruptions

Implementation Roadmap (Week-by-Week)

Week 1: Media Inventory and Classification

  • Inventory all storage media in the organization
  • Map media to the information classification scheme (Public, Internal, Confidential, Secret)
  • Identify all media locations (on-site, off-site, employee possession, vendor possession)
  • Document media types, quantities, and sensitivity levels
  • Identify gaps in media control (untracked media, unclassified media, unprotected media)

Week 2: Policy and Procedure Development

  • Draft storage media management policy
  • Define media classification and labeling requirements
  • Create secure storage requirements for each classification level
  • Develop media transfer and movement procedures
  • Create media disposal and destruction procedures
  • Define backup media rotation and retention requirements
  • Develop media audit and accountability procedures

Week 3: Secure Storage Implementation

  • Designate secure storage areas for each media classification level
  • Install lockable cabinets, safes, or media vaults
  • Implement access controls for media storage areas (key cards, biometrics)
  • Install environmental monitoring (temperature, humidity) for media storage
  • Deploy fire-resistant safes for critical media
  • Create off-site storage arrangement for backup media

Week 4: Access Control and Tracking

  • Implement media checkout system (log who takes what, when, and why)
  • Deploy media labeling system (classification, owner, date, contents)
  • Configure encryption at rest for all removable media
  • Implement DLP (Data Loss Prevention) to control media usage on endpoints
  • Disable or restrict USB ports where not required
  • Create media movement authorization process

Week 5: Disposal Process Setup

  • Procure media destruction equipment (shredders, degaussers) or identify certified disposal vendors
  • Create destruction certificates and logs
  • Define disposal procedures for each media type
  • Create witness requirements for destruction of highly sensitive media
  • Establish chain of custody for media sent to disposal vendors
  • Create disposal vendor evaluation criteria and contracts

Week 6: Backup Media Management

  • Document backup media rotation scheme (daily, weekly, monthly, yearly)
  • Create backup media catalog with retention periods
  • Verify off-site storage provider security and compliance
  • Implement backup media integrity testing (restore tests)
  • Create backup media retrieval procedures
  • Label all backup media with backup date, contents, and retention period

Week 7: Training and Communication

  • Develop media management training for all staff
  • Create quick reference cards for media handling
  • Train IT staff on media classification, storage, and disposal
  • Train managers on media audit and accountability
  • Communicate policy to all employees via email and meetings
  • Post reminders near printers, copiers, and shared storage areas

Week 8: Audit and Validation

  • Conduct internal audit of media management controls
  • Verify all media is classified, labeled, and stored appropriately
  • Test disposal procedures with sample media
  • Verify backup media integrity with restore tests
  • Review access logs for media storage areas
  • Prepare documentation for external audit

Detailed Implementation Guidance

Figure · Tiers

Maturity levels for storage media

  1. SecretStrict handling
  2. ConfidentialControlled handling
  3. InternalBasic handling
  4. PublicNo special handling
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Media Classification and Labeling

Classification Levels:

ClassificationMedia HandlingStorageTransferDisposal
PublicNo special handlingStandard storageNo restrictionStandard disposal
InternalBasic handlingLockable cabinetInternal mail onlyShredding (paper) / Overwriting (digital)
ConfidentialControlled handlingSecure safe or vaultAuthorized courier, encryptedSecure destruction with certificate
SecretStrict handlingFire-resistant safe, vaultEscorted courier, encrypted, sealedWitnessed destruction, certificate

Labeling Requirements:

Every media item must be labeled with:

  1. Classification (Public, Internal, Confidential, Secret)
  2. Content description (e.g., "Customer Database Backup, March 2026")
  3. Date created
  4. Retention period (e.g., "Retain until 2027-03-31")
  5. Owner/department
  6. Unique identifier (for tracking)

Labeling Best Practices:

  • Use color-coded labels (e.g., green for Public, yellow for Internal, orange for Confidential, red for Secret)
  • Use tamper-evident labels for high-sensitivity media
  • Label both the media and its storage container
  • Use barcodes or QR codes for electronic tracking
  • Include "Return to [owner] if found" on portable media

Secure Storage Requirements

On-Site Storage:

ClassificationStorage TypeAccess ControlEnvironmental Control
PublicStandard shelvesUnrestrictedStandard office
InternalLockable cabinetKey or badge accessStandard office
ConfidentialSafe or media vaultBiometric or dual-keyClimate-controlled (18–24°C, 40–50% RH)
SecretFire-resistant safe, vaultTwo-person rule, biometricsClimate-controlled, monitored 24/7

Off-Site Storage:

  • Off-site storage provider must be vetted and contractually bound to security requirements
  • Off-site storage must have equivalent or greater security than on-site
  • Off-site storage must have climate control for sensitive media
  • Transport to off-site must use authorized couriers with tracking
  • Off-site inventory must be reconciled with on-site records quarterly

Media Vault Requirements:

  • Fire resistance: minimum 1 hour (2 hours for Secret media)
  • Water resistance: sealed against flooding
  • Climate control: 18–24°C, 40–50% relative humidity
  • Access control: logged, restricted, monitored
  • Intrusion detection: alarms, CCTV
  • Inventory management: electronic tracking system

Media Transfer and Movement

Internal Transfer:

  • Media must be transported in sealed, labeled containers
  • Confidential and Secret media must be hand-carried, not sent via internal mail
  • Transfer must be logged in the media movement register
  • Recipient must acknowledge receipt
  • Media must not be left unattended during transfer

External Transfer:

  • Pre-approval from data owner and security team required
  • Media must be encrypted with strong encryption (AES-256)
  • Use authorized courier services with tracking and insurance
  • Seal media with tamper-evident seals
  • Document chain of custody
  • Require signed receipt at destination
  • Verify delivery within expected timeframe

Employee Transport:

  • Employees should not transport Confidential or Secret media without authorization
  • If transport is necessary, media must be encrypted
  • Laptops and devices must use full-disk encryption
  • Employees must report lost or stolen media immediately
  • Media must not be left in vehicles unattended

Media Disposal and Destruction

Disposal Methods by Media Type:

Media TypeSanitization MethodDestruction MethodVerification
Hard drives (HDD)Degaussing or secure erase (DoD 5220.22-M)Shredding or crushingCertificate of destruction, serial number log
Solid-state drives (SSD)Cryptographic erase (if supported)Shredding or incinerationCertificate of destruction
USB drives / flash mediaSecure erase or encryptionShredding or incinerationCertificate of destruction
TapesDegaussingShredding or incinerationCertificate of destruction, degaussing log
CDs/DVDsNot applicableShredding or incinerationCertificate of destruction
Paper documentsNot applicableCross-cut shredding (minimum DIN P-3)Certificate of destruction
Mobile devicesFactory reset + encryption wipeShredding or component destructionCertificate of destruction

Disposal Procedures:

  1. Request: Media owner requests disposal with justification
  2. Approval: Data owner and security team approve disposal
  3. Inventory Update: Mark media as "pending disposal" in inventory
  4. Sanitization: Perform data sanitization (overwrite, degauss, or encrypt-wipe)
  5. Destruction: Physical destruction by certified method
  6. Verification: Witness destruction for Secret media; photograph for Confidential
  7. Certificate: Issue certificate of destruction with media details, method, date, witness
  8. Inventory Update: Remove media from inventory; retain destruction record

Disposal Vendor Management:

  • Vendors must be security-vetted and sign NDAs
  • Vendors must provide certificates of destruction
  • Vendors must allow audit of their destruction processes
  • Vendors must have environmental licenses for e-waste disposal
  • Chain of custody must be documented from handover to destruction
  • In India, vendors must comply with E-Waste (Management) Rules, 2022

Backup Media Management

Rotation Schemes:

TypeFrequencyRetentionStorage LocationExample
DailyEvery business day7 daysOn-siteMonday–Sunday overwrite
WeeklyEnd of week4 weeksOff-siteWeek 1, Week 2, Week 3, Week 4 rotation
MonthlyEnd of month12 monthsOff-siteMonth 1–12 rotation
YearlyEnd of year7 yearsOff-site vaultYear 1–7 retention
GrandfatherMonthly + YearlyPer regulatory requirementOff-site vaultCompliance retention

Backup Media Integrity:

  • Test restore from backup media at least quarterly
  • Verify backup media is readable before sending off-site
  • Document restore test results
  • Replace media that fails integrity checks
  • Maintain backup media catalog with test history

Tools, Technologies, and Solutions

Media Encryption Solutions

VendorProductBest Forlicensing Range (INR)
MicrosoftBitLocker (Windows)Full-disk encryption for Windows devicesIncluded in Windows Pro/Enterprise
AppleFileVault (macOS)Full-disk encryption for Mac devicesIncluded in macOS
VeraCryptOpen-source encryptionCross-platform, freeFree
SymantecEndpoint EncryptionEnterprise, central management
McAfeeComplete Data ProtectionEnterprise, DLP + encryption
SophosSafeGuard EncryptionEnterprise, easy deployment

Degaussing Equipment

ProductTypeCapacitylicensing Range (INR)
Garner HD-2Hard drive degausserHDDs, tapes
Garner PD-5Physical destroyer + degausserHDDs, SSDs
Verity Systems SV91MDegausserTapes, HDDs
Proton T-1.5DegausserTapes, HDDs

Shredding Equipment

ProductTypeCapacitylicensing Range (INR)
HSM ShredderCross-cut paper shredderUp to 20 sheets
Kobra ShredderHeavy-duty paper + mediaPaper, CDs, cards
** intimus**Industrial shredderPaper, media, hard drives
DatastroyerMedia shredderHDDs, SSDs, tapes

Media Inventory and Tracking Software

VendorProductKey Featureslicensing Range (INR)
Wasp BarcodeAssetCloudBarcode/RFID tracking, check-in/out
Snipe-ITOpen-source asset managementFree, web-based, media trackingFree (self-hosted)
FreshserviceIT Asset ManagementCloud-based, integrated with ITSM
ServiceNowIT Asset ManagementEnterprise, complete
ManageEngineAssetExplorerGrowing companies, feature-rich

Data Loss Prevention (DLP)

VendorProductKey Featureslicensing Range (INR)
SymantecData Loss PreventionEndpoint, network, cloud
ForcepointDLPUser behavior analytics, cloud
MicrosoftPurview DLPIntegrated with M365
Digital GuardianDLPEndpoint-focused, data classification
ManageEngineEndpoint DLP PlusIndian growing companies, efficient

Policy and Procedure Templates

Storage Media Management Policy Template

Template

Media Disposal Procedure Template

Template


Risk Assessment and Treatment

Risk Assessment Matrix for Storage Media

Risk IDThreatVulnerabilityLikelihoodImpactRisk LevelTreatment
R1Lost USB drive with customer dataNo encryption on removable mediaHighHighCriticalEncrypt all removable media; DLP controls
R2Backup tape stolen from off-siteNo encryption on backup tapesMediumHighHighEncrypt backup tapes; vet off-site provider
R3Hard drive sold with recoverable dataImproper sanitization before disposalMediumHighHighSecure erase + physical destruction; certificate
R4Employee takes confidential documents homeNo media checkout controlMediumHighHighMedia checkout system; employee agreement
R5Printed documents left in recyclingNo secure disposal for paperHighMediumHighShredding bins; secure disposal procedures
R6Media damaged by environmental factorsNo climate control for storageMediumMediumMediumClimate-controlled storage; monitoring
R7Unauthorized media access in storageWeak access controlsMediumHighHighBiometric access; CCTV; access logs
R8Backup media fails during restoreNo integrity testingMediumHighHighQuarterly restore tests; replace failing media
R9Media lost in transitUnencrypted transfer; no trackingMediumHighHighEncrypt; authorized courier; tracking
R10Employee copies data to personal mediaNo DLP; unrestricted USB portsHighHighCriticalDLP; USB port restrictions; awareness

Audit and Compliance Checklist

Internal Audit Checklist (30 Questions)

Policy and Documentation (5 Questions)

  1. Is a storage media management policy documented and approved?
  2. Is the media classification scheme aligned with the information classification scheme?
  3. Are media disposal procedures documented?
  4. Is the backup media rotation scheme documented?
  5. Is the policy reviewed annually?

Inventory and Classification (5 Questions)

  1. Is there a complete inventory of all storage media?
  2. Is all media classified and labeled?
  3. Are media locations documented and current?
  4. Is media ownership assigned?
  5. Is the inventory reconciled quarterly?

Secure Storage (5 Questions)

  1. Is media stored according to classification?
  2. Are Confidential/Secret media in secure storage?
  3. Is access to media storage controlled and logged?
  4. Is off-site storage secure and climate-controlled?
  5. Is media storage protected from fire, water, and theft?

Transfer and Movement (5 Questions)

  1. Is media transfer logged and authorized?
  2. Is external media transfer encrypted?
  3. Are authorized couriers used for external transfer?
  4. Is chain of custody documented?
  5. Are employees trained on media transport rules?

Disposal (5 Questions)

  1. Is media disposal authorized and documented?
  2. Are destruction methods appropriate for media type?
  3. Are certificates of destruction issued and retained?
  4. Is Secret media destruction witnessed?
  5. Are disposal vendors vetted and audited?

Backup and Integrity (5 Questions)

  1. Is backup media rotated according to scheme?
  2. Are backup media integrity tests conducted quarterly?
  3. Is off-site backup inventory reconciled?
  4. Are backup media retention periods documented?
  5. Are backup media protected during transport?

Audit Scoring

  • 30–27: Excellent (Green), Full compliance
  • 26–22: Good (Yellow), Minor gaps, address within 30 days
  • 21–15: Needs Improvement (Orange), Significant gaps, address within 60 days
  • 14–0: Critical (Red), Major non-compliance, immediate action required

Metrics and KPIs

Figure · Measures

The measures that show A.7.10 is working

  • Media Classification Coverage100%Quarterly
  • Media Inventory Accuracy>= 98%Quarterly
  • Encryption Coverage100%Monthly
  • Media Disposal Compliance100%Monthly
  • Certificate of Destruction Coverage100%Monthly
Targets and reporting cadence as defined in the table below, where the formula for each is given.

Key Performance Indicators

KPIFormulaTargetMeasurement Frequency
Media Classification Coverage(Classified media / Total media) x 100100%Quarterly
Media Inventory Accuracy(Accurate records / Total records checked) x 100>= 98%Quarterly
Encryption Coverage (Removable Media)(Encrypted media / Total removable media) x 100100%Monthly
Media Disposal Compliance(Properly disposed media / Total disposed media) x 100100%Monthly
Certificate of Destruction Coverage(Media with certificates / Total destroyed media) x 100100%Monthly
Lost Media IncidentsCount of lost or stolen media incidents0Monthly
Lost Media Reporting TimeAverage time from loss to report<= 1 hourPer incident
Backup Media Integrity Test Pass Rate(Passed tests / Total tests) x 100100%Quarterly
Off-Site Storage Reconciliation(Reconciled quarters / Total quarters) x 100100%Quarterly
DLP Block Rate (USB)(Blocked USB transfers / Attempted USB transfers) x 100>= 90%Monthly
Media Transfer Authorization Rate(Authorized transfers / Total transfers) x 100100%Monthly
Media Storage Access Audit(Access logs reviewed / Required reviews) x 100100%Monthly
Policy Review Cycle Adherence(Reviews on time / Required reviews) x 100100%Annually
Audit Finding Closure Rate(Closed findings / Total findings) x 100100% within 60 daysPer audit
E-Waste Disposal Compliance(Compliant disposals / Total disposals) x 100100%Quarterly

Common Pitfalls and How to Avoid Them

Pitfall 1: No Media Inventory

Problem: The organization has no idea how many USB drives, tapes, or external hard drives exist. Media is purchased, used, and lost without any tracking. Solution: Implement a media inventory system. Use barcode or RFID tracking. Require check-in/check-out for all removable media. Conduct periodic physical audits. Start with the most sensitive media and expand coverage.

Pitfall 2: Unencrypted Removable Media

Problem: USB drives and external hard drives are used without encryption. When lost, the data is immediately accessible. Solution: Mandate encryption for all removable media. Use centrally managed encryption (BitLocker, FileVault, or enterprise solutions). Deploy DLP to block unencrypted transfers. Provide approved encrypted media to staff. Make encryption the default, not optional.

Pitfall 3: Inadequate Disposal

Problem: Hard drives are "deleted" using standard delete or format, which is easily recoverable. Paper is thrown in regular trash. Old devices are sold on the secondary market without proper sanitization. Solution: Use secure erase standards (DoD 5220.22-M, NIST 800-88). Degauss magnetic media. Physically destroy media that cannot be securely erased. Use cross-cut shredders for paper. Vet and contract certified disposal vendors. Never sell equipment without verified destruction of all storage components.

Pitfall 4: Weak Off-Site Storage Controls

Problem: Backup tapes are sent to a "storage company" with no security vetting. The storage company has no climate control, no access controls, and no accountability. Tapes are lost or damaged without detection. Solution: Vet off-site storage providers rigorously. Require security certifications (ISO 27001, SOC 2). Visit the facility. Require chain of custody documentation. Verify climate control and access controls. Reconcile inventory quarterly. Encrypt all backup media before sending off-site.

Pitfall 5: No Backup Media Integrity Testing

Problem: Backup media is created and stored but never tested. When disaster strikes, the backups are corrupted, incomplete, or unreadable. Solution: Test restore from backup media quarterly. Document test results. Replace media that fails testing. Maintain a backup media catalog with test history. Rotate media before end of life. Use backup software that verifies integrity automatically.

Pitfall 6: Ignoring Paper Media

Problem: Organizations focus on digital media but neglect printed documents. Board resolutions, financial statements, and customer lists are printed and left unsecured. Solution: Extend media management to paper. Use secure print (pull printing). Provide shredding bins. Train staff on paper security. Include printers and copiers in spot checks. Consider going paperless where possible.

Pitfall 7: Personal Devices as Media

Problem: Employees use personal USB drives, external hard drives, and smartphones to store work data. These devices are not managed, encrypted, or inventoried. Solution: Prohibit personal media for work data (or allow only with MDM and encryption). Provide approved, managed, encrypted media. Use DLP to detect unauthorized transfers. Include personal device media in policy and awareness training.

Pitfall 8: Vendor and Contractor Media

Problem: Third-party vendors and contractors bring their own media into the organization, or take organizational media off-site, without controls. Solution: Include media management in vendor contracts and NDAs. Require encryption for any vendor media containing organizational data. Monitor vendor access to sensitive areas. Require return or destruction of all media at contract end. Audit vendor media handling.


Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian Healthcare Provider, Backup Tape Transformation (Growing company)

Organization: A 500-bed hospital chain in South India with 3 hospitals, 2,000 employees Challenge: The hospital had been using backup tapes for 10 years without a proper management system. Tapes were stored in a unlocked cabinet in the IT office. There was no inventory, no encryption, no rotation scheme, and no integrity testing. When the IT office was renovated, 47 tapes were found under a desk, covered in dust. The labels were faded; no one knew what data they contained. A ransomware incident revealed that the "active" backup tapes were corrupted and unreadable. Before State:

  • 200+ backup tapes with no inventory
  • Tapes stored in unlocked cabinet, no climate control
  • No encryption on any tape
  • No rotation scheme; tapes overwritten randomly
  • No integrity testing in 5 years
  • Off-site storage: one IT employee took tapes home in his backpack

Implementation: Month 1: Inventoried all tapes. Classified by contents. Destroyed 47 unlabeled tapes with certificate. Month 2: Implemented new backup media policy. Defined rotation scheme (daily, weekly, monthly, yearly). Month 3: Purchased encrypted tape drives (LTO-8 with encryption). Deployed new backup software with integrity verification. Month 4: Contracted with professional off-site storage provider (vetted, ISO 27001 certified). Implemented chain of custody. Month 5: Conducted quarterly restore tests. Replaced failing tapes. Month 6: Trained all IT staff on media management. Created quick reference guides.

Results (After 12 Months):

  • 100% of backup media encrypted
  • 100% inventory accuracy (tracked via barcode system)
  • Restore test pass rate: 100% (quarterly)
  • Off-site storage: professional vault with climate control, 24/7 security
  • Zero lost or unaccounted media incidents
  • Ransomware recovery successful: 4-hour RTO, 1-hour RPO achieved
  • NABH accreditation achieved (media management was a requirement)

Investment: (tape drives, encryption, off-site storage contract, inventory system, training) ROI: The ransomware incident would have overhead in recovery and reputation damage if backups had failed. The new system enabled rapid recovery and accreditation that increased patient trust and revenue.

Key Lesson: Backup media is not "set and forget." It requires active management, integrity testing, and professional storage. The hospital's decade of neglect created a ticking time bomb that nearly destroyed the organization.


Illustrative Scenario 2: Large Indian IT Services Company, Global Media Standardization

Organization: An IT services company with 8,000+ employees, 5 delivery centers across India, and clients in 15 countries Challenge: The company had grown through acquisition, resulting in 5 delivery centers with completely different media management practices. The Bengaluru center had excellent controls (encrypted media, professional disposal, DLP). The Pune center (acquired 3 years ago) had no controls, employees freely used USB drives, no encryption, no inventory, and hard drives were sold to a local scrap dealer without sanitization. A client audit of the Pune center discovered the gap and threatened contract termination. Before State:

  • 5 delivery centers with varying media controls
  • Bengaluru: excellent controls; Pune: no controls
  • No global media management policy
  • 3,000+ employees with uncontrolled USB access
  • No DLP deployment in 3 of 5 centers
  • Hard drives from retired equipment sold to scrap dealers without sanitization
  • No centralized media inventory or tracking

Implementation: Phase 1 (Months 1–2): Developed global media management policy. Defined minimum standards for all centers. Phase 2 (Months 3–4): Deployed DLP across all 5 centers (Symantec DLP). Restricted USB ports where not required. Phase 3 (Months 5–6): Deployed centrally managed encryption (BitLocker for Windows, FileVault for Mac). Issued approved encrypted USB drives to staff who needed them. Phase 4 (Months 7–8): Implemented centralized media inventory (ServiceNow Asset Management). Barcoded all media. Phase 5 (Months 9–10): Contracted with certified e-waste disposal vendor for all centers. Implemented destruction certificate process. Phase 6 (Months 11–12): Trained all 8,000 employees. Conducted global internal audit. Client re-audit.

Results (After 12 Months):

  • 100% of delivery centers compliant with global media policy
  • DLP deployment: 100% coverage
  • Encryption: 100% of removable media and endpoint devices
  • Media inventory: 95%+ accuracy
  • E-waste disposal: 100% certified destruction
  • Client re-audit: passed with zero findings
  • Two new clients signed, citing security maturity

Investment: (DLP, encryption, inventory system, disposal vendor, training, audit)

Key Lesson: Growth through acquisition creates security gaps. The weakest center becomes the liability for the entire organization. Global companies need global standards, centralized enforcement, and consistent accountability.


Multi-Framework Mapping

ISO 27001:2022 A.7.10 to Other Frameworks

ISO 27001:2022 A.7.10NIST 800-53 Rev 5PCI DSS v4.0SOC 2 CC6.1CIS Controls v8COBIT 2019
Storage media managementMP-2 (Media Marking)Req 9.5 (Physical Security of Media)CC6.1 (Logical and Physical Access)CIS 3.2 (Data Classification)DSS05.04 (Manage Physical Security)
Media encryptionSC-28 (Protection of Data at Rest)Req 3.4 (Render PAN Unreadable)CC6.1CIS 3.10 (Encrypt Sensitive Data)DSS05.04
Media disposalMP-6 (Media Sanitization)Req 9.5CC6.1CIS 3.11 (Data Recovery)DSS05.04
Media transferMP-5 (Media Transport)Req 9.5CC6.1CIS 3.12 (Data Retention)DSS05.04
Backup mediaCP-9 (System Backup)Req 9.5CC6.1CIS 11.1 (Data Recovery)DSS05.04

NIST 800-53 Rev 5:

  • MP-2: Media Marking, Maps to media classification and labeling
  • MP-5: Media Transport, Maps to media transfer and movement
  • MP-6: Media Sanitization, Maps to media disposal and destruction
  • MP-7: Media Use, Maps to removable media restrictions
  • SC-28: Protection of Data at Rest, Maps to encryption at rest
  • CP-9: System Backup, Maps to backup media management

PCI DSS v4.0:

  • Requirement 3.4: Render PAN unreadable on all media
  • Requirement 9.5: Physical security of media and backup materials
  • Requirement 9.6: Physical security of paper media
  • Requirement 9.7: Maintenance of media inventories

SOC 2 CC6.1:

  • Logical and physical access controls for stored data
  • CC6.7: Physical security of systems and data

CIS Controls v8:

  • CIS Control 3: Data Protection, Media classification, encryption, disposal
  • CIS Control 11: Data Recovery, Backup media integrity and testing

Regulatory and Industry Context

India-Specific Regulatory Requirements

Digital Personal Data Protection (DPDP) Act 2023:

  • Section 8(5): Reasonable security safeguards for personal data on all media
  • Section 10: Breach notification within 72 hours of becoming aware
  • Penalties up to for failure to protect personal data
  • Data fiduciaries must ensure personal data is protected on physical media

Information Technology Act 2000 (as amended):

  • Section 43A: Compensation for failure to protect sensitive personal data
  • Section 72: Breach of confidentiality and privacy
  • Section 66C: Identity theft (applicable to stolen media containing identity data)

E-Waste (Management) Rules, 2022:

  • Electronic waste (including storage media) must be disposed of through authorized recyclers
  • Organizations must maintain records of e-waste generation and disposal
  • Extended Producer Responsibility (EPR) for manufacturers; best practice for all organizations
  • E-waste must be handed to authorized collection centers or registered recyclers

RBI Cyber Security Framework:

  • Backup media must be encrypted and stored securely
  • Off-site storage required for critical banking data
  • Media integrity must be verified periodically
  • Disposal must ensure data is irrecoverable

SEBI Cybersecurity Circular:

  • Trading data backup media must be protected
  • Media storage must be in controlled environments
  • Retention periods must comply with regulatory requirements

Industry-Specific Context

BFSI:

  • RBI mandates encryption for all backup media containing customer data
  • Off-site storage must be at least 50 km from primary site
  • Media retention: 7 years for most financial records
  • Quarterly restore testing required for critical systems

Healthcare:

  • Patient data on media must be encrypted (equivalent to HIPAA requirements)
  • Medical images (DICOM) on portable media must be traceable
  • Retention: lifetime of patient + 7 years for records
  • Disposal must ensure no recoverable patient data

Government:

  • Classified media must be stored in approved facilities
  • Disposal of classified media requires witnessing and certificate
  • Media handling must comply with Ministry of Home Affairs guidelines
  • RTI Act requirements for record retention and disposal

IT/ITES:

  • Client data on media must meet client contractual requirements
  • Offshore development centers often have strict client media controls
  • Media audits are common in client security assessments

Roles and Responsibilities (RACI)

ActivityCISOData Protection OfficerIT OperationsIT SecurityFacility MgmtAll Employees
Policy DevelopmentARCRII
Media ClassificationCACRIC
Inventory ManagementCCRCII
Secure StorageCCRCRI
Encryption DeploymentACRRII
Media TransferCCRRII
Disposal OversightARCRCI
Backup Media ManagementCCRCII
Integrity TestingCCRCII
Training and AwarenessARCRIR
Incident ResponseARCRII
Audit and ComplianceACCRII
Vendor ManagementCCRRII
Continuous ImprovementARCCII

Documentation and Evidence Requirements

DocumentPurposeRetention PeriodOwner
Storage Media Management PolicyDefines requirementsDuration + 3 yearsCISO
Media InventoryAsset trackingDuration + 3 yearsIT Operations
Media Classification MatrixSensitivity mappingDuration + 3 yearsDPO
Media Transfer LogMovement tracking1 yearIT Operations
Destruction CertificatesDisposal evidenceDuration + 3 yearsIT Security
Destruction LogDisposal trackingDuration + 3 yearsIT Security
Backup Media CatalogBackup trackingDuration + 3 yearsIT Operations
Restore Test ResultsIntegrity evidenceDuration + 3 yearsIT Operations
Off-Site Storage AgreementVendor contractDuration + 3 yearsIT Operations
Off-Site Inventory ReconciliationAccuracy verification1 yearIT Operations
Access Control LogsStorage access evidence1 yearIT Security
Training RecordsAwareness evidenceDuration + 3 yearsHR
Audit Checklist and ResultsAudit evidenceDuration + 3 yearsInternal Audit
Risk AssessmentRisk treatment evidenceDuration + 3 yearsCISO
Exception LogApproved exceptionsDuration + 3 yearsCISO
E-Waste Disposal RecordsEnvironmental complianceDuration + 3 yearsFacility

Continuous Improvement

Maturity Model for A.7.10

LevelNameCharacteristicsEvidence
1InitialNo media inventory; no controls; media lost and disposed of ad-hocNo policy; no inventory; no encryption; no disposal records
2DevelopingBasic inventory; some controls; reactive managementPartial inventory; some encryption; informal disposal
3DefinedFull inventory; all controls implemented; proactive managementComplete inventory; all media encrypted; secure storage; disposal certificates
4ManagedMetrics-driven; automated tracking; predictive managementAutomated inventory; DLP; quarterly integrity tests; trend analysis
5OptimizedFully automated; self-managing; integrated with enterprise systemsAI-powered classification; blockchain tracking; automated disposal; zero incidents

Continuous Improvement Activities

Monthly:

  • Media inventory reconciliation
  • Disposal certificate review
  • Lost media incident review
  • DLP reporting analysis

Quarterly:

  • Backup media integrity testing
  • Off-site inventory reconciliation
  • Internal audit of media controls
  • Vendor performance review
  • Training effectiveness assessment

Annually:

  • Full policy review
  • Complete risk assessment refresh
  • Technology and tool review
  • Benchmark against industry standards
  • External audit preparation
  • Maturity assessment against target level

Trigger-Based:

  • After any media-related incident
  • Upon new media technology adoption
  • When regulatory requirements change
  • After significant audit findings
  • Upon organizational change (merger, acquisition)

FAQ

Q1: What types of media does A.7.10 cover? A: All physical storage media containing organizational information: hard drives, SSDs, USB drives, CDs/DVDs, tapes, memory cards, paper documents, microfilm, and mobile devices with storage. If it holds information, it is in scope.

Q2: Do we need to encrypt backup tapes? A: Yes, strongly recommended. Backup tapes are frequently transported and stored off-site, making them high-risk. Encryption ensures that even if a tape is lost or stolen, the data is unreadable. Modern LTO tapes (LTO-4 and later) support hardware encryption. Software encryption is also effective.

Q3: How do we securely dispose of SSDs? A: SSDs are challenging because traditional overwrite methods may not reach all flash cells. The most reliable methods are: (1) Cryptographic erase (if the SSD supports it), (2) Physical destruction (shredding, crushing, or incineration). Degaussing does not work on SSDs (they are not magnetic). Always verify destruction and obtain a certificate.

Q4: Can we use cloud backup instead of physical media? A: Cloud backup is an excellent complement or replacement for physical backup media, but it does not eliminate all media management concerns. You still need to manage the physical devices that access cloud data, ensure encryption in transit and at rest, verify cloud provider security, and maintain offline/offline backup capability. Cloud does not eliminate A.7.10, it changes the implementation.

Q5: What is the retention period for destruction certificates? A: Retain destruction certificates for the duration of the information's retention period plus 3 years. For example, if financial records must be retained for 7 years, retain destruction certificates for 10 years. This provides audit evidence and legal protection.

Q6: Do we need to manage printed documents? A: Yes. Printed documents are a form of storage media. They must be classified, stored securely, and disposed of via shredding. Many breaches involve printed documents left in meeting rooms, at printers, or in recycling bins. Include paper in your media management program.

Q7: How do we handle media in employee home offices? A: Extend media management to remote work. Provide approved encrypted media for remote employees. Prohibit personal USB drives for work data. Use DLP to detect unauthorized transfers. Include remote media in inventory. Require secure storage at home (locked drawer). Include remote media in policy and training.

Q8: What is the best DLP solution for a growing Indian company? A: For growing companies, consider: Microsoft Purview DLP (if using M365), ManageEngine Endpoint DLP Plus (efficient, good for Indian market), or Symantec DLP (complete but more premium-tier). The best choice depends on your existing infrastructure, budget, and specific requirements. A phased approach is often most effective.

Q9: How do we verify that a disposal vendor actually destroys media? A: (1) Vet the vendor before contracting (visit their facility, check certifications). (2) Require certificates of destruction with serial numbers. (3) Conduct periodic audits of their processes. (4) Use your own witnessing for Secret media. (5) For high volumes, consider on-site destruction using your own equipment. (6) Verify their environmental licenses (e-waste rules compliance).

Q10: What is the most common audit finding for A.7.10? A: Unencrypted removable media. Auditors will check USB drives, external hard drives, and backup tapes for encryption. They will also verify disposal certificates and inventory accuracy. The most common failure is having no evidence that media is encrypted, no inventory, or no disposal certificates.

Q11: How do we manage media for legacy systems? A: Legacy systems often use obsolete media (floppy disks, ZIP drives, tape formats). These must be included in media management. Transfer data to modern media if possible. If legacy media must be retained, store it in climate-controlled conditions (older media is more fragile). Document the contents and retention requirements. Plan for eventual migration or destruction.

Q12: What about media in copiers and printers? A: Modern copiers and printers have hard drives that store copies of every document processed. This is a frequently overlooked media risk. Include printer/copier hard drives in your media management program. When disposing of printers, remove and destroy the hard drive. Some manufacturers offer hard drive encryption for printers, enable it.

Q13: How do we handle media during office relocation? A: Office relocation is a high-risk event for media. Create a media relocation plan: (1) Inventory all media before packing, (2) Use tamper-evident containers, (3) Transport Confidential/Secret media with escort, (4) Verify chain of custody, (5) Reconcile inventory at the new location, (6) Verify environmental controls at new storage areas before moving media. Do not leave media unattended during the move.

Q14: How much does implementing A.7.10 overhead? A: For a 200-person growing company: encryption (–), DLP (–), inventory system (–), secure storage (–), disposal equipment/vendor (–), training (–). Total: –This is one of the highest-ROI security investments.

Q15: Can we use personal cloud storage (Google Drive, Dropbox) for work data? A: No, not without proper controls. Personal cloud storage is not part of your organization's media management program. If employees need cloud storage, provide approved enterprise solutions (OneDrive, Google Workspace, Dropbox Business) with MDM, DLP, and encryption. Prohibit personal accounts for work data. Include cloud storage in your media and data management policies.

Industry-Specific Media Management Requirements

Banking and Financial Services (BFSI)

RBI Cyber Security Framework Requirements:

  • Data Localization: All customer financial data must be stored on media within India. Primary and backup copies in Indian data centers only.
  • Encryption Standards: AES-256 for data at rest on all media (hard drives, SSDs, tapes, USB). HSMs for key management.
  • Retention Periods: Transaction records: 7 years (SEBI), 8 years (RBI). Loan records: 12 years. Audit logs: 7 years.
  • Immutable Storage: Audit logs and transaction records must be stored on tamper-proof media (WORM tape, blockchain-based logging).
  • Media Disposal: Physical destruction (degaussing, shredding) for all media containing customer data. No resale or donation of used storage media.
  • Third-Party Media: Cloud storage providers must be RBI-approved and data must remain within India. Media handling clauses in all vendor contracts.

BFSI Media Architecture Example:

Primary Storage (Tier 1)
├── Core Banking: SSD arrays with synchronous replication
├── ATM Network: SSD at each ATM site, centralized to primary DC
├── Trading Platform: Ultra-low latency SSD, in-memory databases
└── Analytics: Hybrid SSD/HDD for data warehouse

Backup Storage (Tier 2)
├── Daily Backups: HDD-based backup appliances
├── Weekly Backups: Tape library (LTO-9, encrypted)
├── Monthly Archives: WORM tape for regulatory compliance
└── Immutable Logs: Blockchain-based or WORM storage

Disposal Process
├── HDD/SSD: Physical shredding (particle size < 2mm per NIST 800-88)
├── Tape: Degaussing + shredding
├── USB/Optical: Physical destruction
└── Documentation: Certificate of destruction for each item

Healthcare

NABH and Data Protection Requirements:

  • Patient Data Encryption: All patient health records (PHI) must be encrypted at rest on all media. Separate encryption keys per department.
  • Retention Periods: Outpatient records: 3 years. Inpatient records: 10 years. Medico-legal cases: Until case resolution + 10 years.
  • Imaging Data (PACS): DICOM images stored on redundant media with 99.99% availability. Long-term archive on tape or cloud.
  • Anonymization: Research datasets must be de-identified before storage on research media.
  • Mobile Media: USB drives, laptops, and tablets used for patient data must be encrypted and inventoried. Loss of any mobile media must be reported as a breach.
  • Media Disposal: All media containing PHI must be physically destroyed (not just wiped). Certificate of destruction required.

Government and Critical Infrastructure

NCIIPC and MeitY Requirements:

  • Classification-Based Media Handling: Top Secret, Secret, and Confidential data require different media handling procedures.
  • Air-Gapped Media: Critical infrastructure systems must use dedicated media that never connects to the internet or other networks.
  • Media Transfer: Physical transfer of classified media requires escort, chain of custody, and tamper-evident packaging.
  • Citizen Data: Aadhaar, PAN, and tax data must be stored on encrypted media within India. No cross-border transfer on physical media.
  • Election Data: EVM and voter roll data stored on dedicated, tamper-evident media. Post-election media must be securely archived.
  • Defense Media: Military storage media must meet defense specifications ( ruggedized, encrypted, tamper-detecting).

IT/ITeS and SaaS

Cloud and Multi-Tenant Media Requirements:

  • Tenant Isolation: Each tenant's data must be on logically isolated media. No cross-tenant media sharing.
  • Data Residency: Indian customer data stored on media in Indian data centers (AWS Mumbai, Azure Pune, GCP Delhi).
  • Media Lifecycle: Cloud storage media (SSD, HDD) managed by provider, but customer responsible for data classification and retention.
  • API and Backup Media: API keys, backup credentials, and configuration data stored in encrypted vaults (HashiCorp Vault, AWS Secrets Manager).
  • Dev/Prod Separation: Development and production data must be on separate media. No production data on developer workstations or test environments.
  • Customer Key Management: Enterprise customers may require CMEK. Customer-managed keys must be stored on dedicated HSM media.

Manufacturing and Industrial

OT/IT Media Convergence:

  • OT Media Isolation: SCADA, PLC, and DCS configuration data stored on isolated media with no internet connection.
  • Engineering Data: CAD files, product designs, and IP stored on encrypted media with DLP and strict access controls.
  • IoT Device Media: Industrial IoT sensors and edge devices use local storage (SD cards, flash) that must be encrypted and managed.
  • Supply Chain Media: Vendor-provided software and firmware must be verified (hash, signature) before being loaded onto production media.
  • Legacy Equipment: Manufacturing equipment with obsolete media (floppy disks, proprietary formats) requires specialized handling and migration planning.

Media Management Maturity Model

LevelNameMedia CharacteristicsEncryptionInventoryDisposalDocumentation
1InitialAd hoc, no trackingNoneNoneAd hocNone
2ManagedBasic inventory, some encryptionPartialSpreadsheetBasic wipingBasic logs
3DefinedFull inventory, all encryptedAll mediaCMDB/ITSMCertified destructionFull SOPs
4QuantitativeAutomated tracking, DLPAll + keys managedAutomatedAudited, metricsAutomated reports
5OptimizedAI-driven, self-protectingQuantum-readyReal-timeZero-touch, automatedPredictive analytics

Progression Guidance:

  • Level 1 → 2: Create media inventory, implement basic encryption for laptops/USBs, establish disposal process. (Time: 2-4 weeks)
  • Level 2 → 3: Full inventory in CMDB, all media encrypted, certified disposal vendor, complete SOPs. (Time: 1-2 months)
  • Level 3 → 4: Automated discovery, DLP integration, disposal metrics, quarterly audits. (Time: 2-4 months)
  • Level 4 → 5: AI-driven classification, self-encrypting media, automated lifecycle management, predictive disposal. (Time: 6-12 months)

Media Management Metrics and KPIs

MetricFormulaTargetFrequency
Media Inventory Accuracy(Accurate records / Total media items) × 100> 98%Monthly
Encryption Coverage(Encrypted media / Total media) × 100100%Monthly
Media Disposal SLA(Disposals on time / Total disposals) × 100100%Monthly
Lost Media IncidentsNumber of lost or stolen media incidents0Monthly
DLP Block Rate(Blocked exfiltration attempts / Total attempts) × 100> 95%Monthly
Retention Compliance(Media within retention / Total media) × 100100%Quarterly
Disposal Certificate Rate(Media with certificates / Total disposed) × 100100%Monthly
Unused Media Recovery(Reclaimed unused media / Total provisioned) × 100> 20%Quarterly
Cloud Storage overheadoverhead per GB of cloud storageOptimizedMonthly
Media-Related BreachesNumber of breaches caused by media mishandling0Monthly

Additional FAQ

Q16: How do we handle media for AI/ML training datasets? A: AI/ML datasets require massive storage (petabytes for large models). Use object storage for raw data, high-performance storage for training workloads, and version control for dataset versioning. Ensure training data containing PII is anonymized or used with appropriate consent under DPDP Act 2023. Implement data lineage tracking so you can trace which media contains which datasets.

Q17: What is the difference between media sanitization and destruction? A: Sanitization removes data from media so it can be reused (clearing, purging, or cryptographic erasure). Destruction physically destroys the media so it cannot be reused (shredding, degaussing, incineration). For sensitive data, destruction is preferred. For less sensitive data, sanitization may be acceptable. Follow NIST 800-88 guidelines for appropriate methods based on data classification.

Q18: How do we manage media in a Bring Your Own Device (BYOD) environment? A: BYOD devices are personal media that contain work data. Require: (1) MDM enrollment for all BYOD devices, (2) Full-disk encryption enabled, (3) Remote wipe capability, (4) Containerization to separate work and personal data, (5) DLP to prevent data exfiltration, (6) Regular security updates, and (7) Clear policy on what happens to work data when employment ends (remote wipe of work container).

Q19: What about media used by third-party vendors and contractors? A: Third-party media containing your data must be covered by contract: (1) Encryption requirements, (2) Inventory and tracking obligations, (3) Disposal procedures and certificates, (4) Breach notification requirements, (5) Right to audit, and (6) Data return or destruction upon contract termination. Do not assume vendors handle media securely, verify and audit.

Q20: How do we prepare for quantum computing threats to media encryption? A: Quantum computers may eventually break current encryption (RSA, ECC). Prepare by: (1) Monitoring NIST post-quantum cryptography standards, (2) Implementing crypto-agility (ability to swap algorithms without re-architecting), (3) Increasing key lengths where possible, (4) Planning for quantum-resistant algorithms (lattice-based, hash-based), and (5) Protecting long-term archived data with additional layers of security. This is a 5-10 year horizon, not immediate, but worth planning for.

Illustrative Scenario: Delhi IT Services Company, Media Mismanagement to Data Breach

Background

A 200-employee IT services company in Delhi provided software development and data processing for clients in India and the US. They had no formal media management program. USB drives were shared freely, laptops were not encrypted, and old hard drives were sold on the secondary market without data wiping.

The Incident

In November 2024, an old laptop hard drive sold on OLX contained unencrypted customer data from a previous project. The buyer, a cybersecurity enthusiast, discovered the data and reported it to the company. Investigation revealed that 47 hard drives, 12 laptops, and 200+ USB drives had been disposed of without proper sanitization over the past 3 years. The data included:

  • 15,000 customer records (names, emails, phone numbers)
  • 2,000 payment card numbers (partial, but still sensitive)
  • Proprietary client source code and database schemas
  • Internal financial documents

Root Cause Analysis

  1. No Media Policy: There was no policy governing how storage media should be handled, inventoried, or disposed of.
  2. No Encryption: Full-disk encryption was not required on laptops. USB drives were not encrypted. Sensitive data was frequently copied to unencrypted media.
  3. No Disposal Process: Old equipment was sold to employees or on second-hand markets without any data wiping. IT staff assumed "deleting files" was sufficient.
  4. No Inventory: The company had no inventory of storage media. They didn't know how many USB drives, external hard drives, or laptops existed.
  5. No Vendor Vetting: A recycling vendor was used once, but there was no verification of their sanitization process or certificates of destruction.
  6. No DLP: Data Loss Prevention was not implemented. Employees could copy sensitive data to any media without restriction.

Impact

  • Data Breach: 15,000 customer records exposed, triggering notification requirements under US state laws (California CCPA) and DPDP Act 2023
  • Regulatory: DPDP Act violation notice, potential fine of s. US clients threatened legal action under their contracts.
  • Client Loss: 3 major US clients terminated contracts (worth s annually) citing inadequate data handling practices.
  • Reputational: News coverage in Indian tech media. Difficulty hiring talent due to damaged reputation.
  • Total overhead: s (fines, legal, client compensation, remediation, lost revenue).

Remediation

The company engaged Singahi to implement a complete media management program:

Phase 1 (Immediate):

  • Emergency inventory of all current storage media (laptops, desktops, servers, USB drives, external drives, tapes, mobile devices)
  • Immediate deployment of full-disk encryption on all laptops (BitLocker for Windows, FileVault for Mac)
  • Purchase of approved encrypted USB drives for all staff
  • DLP deployment (Microsoft Purview) to prevent unauthorized copying
  • Immediate halt of all equipment disposal until proper process is established

Phase 2 (Month 1-2):

  • Media management policy drafted and approved
  • CMDB implementation for tracking all media assets
  • Secure disposal vendor selected and contracted (with certificate of destruction)
  • Staff training on media handling, encryption, and disposal procedures
  • Old equipment recovery: attempt to retrieve and properly destroy all previously disposed media

Phase 3 (Month 3-4):

  • Automated media discovery tools deployed
  • Cloud storage governance (approved providers, encryption, access controls)
  • Regular media audits (quarterly physical verification)
  • Integration with procurement (new equipment automatically enrolled in inventory)
  • Backup media encryption and off-site storage with chain of custody

Results:

  • 100% of laptops encrypted within 60 days
  • 100% of USB drives replaced with approved encrypted models
  • Zero unauthorized media disposal incidents in 12 months
  • Passed client security audits (regained 2 of 3 lost clients)
  • DLP blocked 450+ attempted unauthorized data copies in the first quarter
  • Total Investment: . Avoided Future overhead: Estimated + crores per incident.

Key Lessons

  1. Media Management is Not Optional: Every storage device is a potential breach vector. Treat media with the same seriousness as network security.
  2. Encryption is the First Line of Defense: If the disposed hard drive had been encrypted, the data would have been unreadable. Encryption is non-negotiable.
  3. Disposal is Part of the Lifecycle: Media security doesn't end when equipment is retired. Proper disposal is as important as proper use.
  4. Inventory Enables Control: You cannot protect what you don't know exists. Automated discovery is essential.
  5. DLP Prevents Accidents: Most data leaks are accidental (wrong USB drive, email to wrong recipient). DLP catches these before they become breaches.

Remote Work and Media Security

The shift to hybrid and remote work has dramatically expanded the media attack surface. Employees now work from home offices, cafes, co-working spaces, and client sites, often using personal devices and public networks. This creates unique media security challenges:

Home Office Risks:

  • Personal Printers: Documents printed at home may be left unattended, seen by family members, or improperly disposed of. Implement print policies that restrict sensitive document printing to office locations or secure home printers.
  • Home Networks: Home WiFi networks are typically less secure than corporate networks. Require VPN for all work-related data access and prohibit sensitive data downloads to personal devices.
  • Shared Devices: Family members using work devices (or vice versa) can lead to accidental data exposure. Implement strict device-use policies and technical controls.
  • Physical Theft: Laptops and mobile devices are more likely to be stolen from home or public places than from offices. Full-disk encryption and remote wipe are essential.

Co-Working Space Risks:

  • Network Snooping: Public WiFi in co-working spaces is easily intercepted. Mandate VPN and prohibit sensitive data transfers on public networks.
  • Visual Eavesdropping: Open floor plans allow anyone to see screens. Require privacy screens for laptops and prohibit work in high-traffic areas.
  • Printer Security: Shared printers in co-working spaces retain copies of printed documents. Avoid printing sensitive materials in shared spaces.
  • USB Charging Stations: Public USB charging stations can be compromised to steal data ("juice jacking"). Prohibit their use for work devices.

Travel Risks:

  • Border Searches: Devices may be inspected at international borders. Encrypt all data and consider using travel-only devices with minimal data.
  • Hotel Room Theft: Laptops left in hotel rooms are vulnerable. Require employees to carry devices or use hotel safes.
  • Airport Security: Devices must go through X-ray machines. While generally safe, sensitive data should be encrypted.
  • Lost Luggage: Checked luggage containing devices may be lost. Carry devices in cabin baggage only.

Remote Work Media Security Policy Checklist:

  • Full-disk encryption required on all work devices
  • VPN mandatory for all work-related data access
  • Remote wipe enabled and tested
  • USB ports disabled or restricted on work devices
  • Cloud storage (approved provider only) used instead of local storage
  • Sensitive data prohibited on personal devices
  • Home printer restrictions defined
  • Co-working space security guidelines provided
  • Travel security guidelines provided
  • Incident reporting procedures for lost/stolen devices

References and Further Reading

Standards and Frameworks

  • ISO/IEC 27001:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Management Systems, Requirements
  • ISO/IEC 27002:2022, Information Security, Cybersecurity and Privacy Protection, Information Security Controls
  • NIST SP 800-53 Rev 5, Security and Privacy Controls for Information Systems and Organizations
  • NIST SP 800-88 Rev 1, Guidelines for Media Sanitization
  • PCI DSS v4.0, Payment Card Industry Data Security Standard
  • CIS Controls v8, CIS Controls Version 8

Indian Regulations

  • Digital Personal Data Protection Act, 2023 (India)
  • Information Technology Act, 2000 (as amended)
  • E-Waste (Management) Rules, 2022 (India)
  • RBI Cyber Security Framework for Banks
  • SEBI Circular CIR/ISD/2019 on Cyber Security and Cyber Resilience

Books and Publications

  • ISO 27001/27002: A Pocket Guide by Alan Calder
  • NIST 800-88: Guidelines for Media Sanitization (NIST)
  • The Security Handbook by Gerald L. Kovacich and Edward Halibozek

Indian Regulatory Context for Storage Media

India's regulatory framework places specific obligations on media handling and disposal. The E-Waste (Management) Rules, 2022 require environmentally sound disposal of electronic equipment, including storage media, through authorized recyclers and with documentation. The DPDP Act 2023 requires that personal data on media be protected by reasonable security safeguards (Section 8(5)) and erased when no longer needed (Section 8(7)), with breaches intimated to the Board and affected principals (Section 8(6)). RBI's Cyber Security Framework mandates encryption of sensitive data at rest and secure disposal of storage media used in banking systems. CERT-In incidents have shown that improper disposal of old laptops and hard drives is a common source of Indian data breaches. Singahi recommends that Indian organizations contract only CERT-In-empaneled or R2/e-Stewards-certified e-waste vendors, obtain certificates of destruction for every batch, and maintain a media disposal register for at least seven years.

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.