ISO 27001 is the international standard for information security management, and secure disposal is written into it. A specific control requires that equipment holding storage media be verified as cleared before it is disposed of or reused. When you choose a disposal provider certified to ISO 27001, you are getting independent evidence of exactly the controls your own obligations expect you to check for. This guide explains how.
ISO 27001 is the international standard for an information security management system, and it addresses disposal directly through Annex A control 7.14, secure disposal or re-use of equipment, which requires that items of equipment containing storage media be verified to ensure sensitive data has been removed or securely overwritten before the equipment is disposed of or reused. In other words, secure disposal is not an add-on to ISO 27001; it is one of the controls an organisation certified to the standard has to have in place and demonstrate. That is why the certification matters when you choose a disposal partner: a provider certified to ISO 27001:2022 has had its information security controls, disposal among them, independently audited, which gives you documented evidence rather than a verbal assurance. ITC's own certifications include ISO 27001:2022.
Businesses hear "ISO 27001-certified" a lot and often take it as a general badge of trustworthiness without knowing what it specifically covers. For disposal, it covers something concrete and useful, and understanding that turns the certification from a logo into a meaningful check. This guide explains what ISO 27001 is, the disposal control inside it, and why a certified provider gives you something an uncertified one cannot: proof.
Not a disposal standard in itself, but the framework for managing information security, with disposal as one control within it.
ISO 27001 is the international standard for an information security management system, published by the International Organization for Standardization. Rather than prescribing a single technical measure, it sets out a framework for how an organisation identifies its information security risks and puts controls in place to manage them, and it is certifiable, meaning an organisation can be independently audited and certified as conforming to it. Its most recent version is ISO 27001:2022. The standard includes a set of reference controls in its Annex A, covering everything from access control and cryptography to physical security and, relevantly here, the handling of equipment at end of life. Because certification is granted by an independent body after an audit, and maintained through ongoing surveillance, an ISO 27001 certificate is not a self-declaration; it is external verification that the controls exist and are operating. You can read about the standard on the ISO website.
A specific, named control makes secure disposal a requirement of the standard, not a matter of good intentions.
Within Annex A of ISO 27001:2022, control 7.14 is titled "Secure disposal or re-use of equipment". Its requirement is direct: items of equipment containing storage media are to be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use. Read carefully, that control captures the whole logic of good disposal in a sentence. It applies to any equipment containing storage media, which is broader than the obvious computers and takes in servers, drives, phones, and the copiers and devices people forget. It requires verification, not just an attempt, so a wipe that failed silently does not satisfy it. And it draws the line at the moment of disposal or reuse, so the control bites exactly when a device leaves its current use, which is the point at which the risk is highest and attention is lowest.
The consequence for an organisation certified to ISO 27001 is that it must be able to show this control is in place: that it has a process for verifying data has been removed or destroyed before equipment is disposed of or reused, and evidence that the process is followed. For most organisations, the practical way to meet that control at scale is to use a disposal provider whose own process is built around it, and certified, so the verification and the evidence come as standard. Our guide to data destruction methods covers how that removal and overwriting is actually done to a recognised standard.
The control does not just say remove the data; it says verify it has been removed or securely overwritten. That single word is why credible disposal ends with confirmation and a certificate rather than a hopeful wipe. Meeting Annex A 7.14 means being able to show, for each device, that the removal was verified, which is precisely what a per-device certificate provides.
Choosing an ISO 27001-certified disposal partner is not just about their security; it is evidence for yours.
When you hand retired equipment to a disposal provider, that provider becomes a third party handling your information at its most vulnerable point. Your own obligations, whether under the Privacy Act's reasonable-steps duty, or for financial institutions under APRA CPS 234, which explicitly requires you to assess the information security capability of parties handling your information assets, expect you to have satisfied yourself that the provider is capable. This is where certification does real work. A provider certified to ISO 27001:2022 has had its information security management system, including its disposal controls under Annex A 7.14, independently audited, so its certificate is objective evidence you can rely on for your own assessment. Instead of taking a provider's word that it handles data securely, you have an external body's verification that it does, which is a far stronger footing when your own compliance is examined.
Any provider can say it destroys data securely. A certified provider has proven it to an independent auditor and is re-audited to keep the certification. For a business relying on that provider to meet its own obligations, that difference, between a claim and independently verified evidence, is the whole point. ITC holds ISO 27001:2022 for information security, alongside its certifications for environmental management, quality and health and safety.
Three things the standard turns from a promise into a documented, audited control.
The reason ISO 27001 is worth looking for in a disposal partner is that it converts the parts of disposal you cannot see into something you can rely on. You will not witness every wipe or shred, and you cannot audit a provider's whole operation yourself. Certification does that for you: an independent body has verified that the provider has the controls, including the disposal control at Annex A 7.14, and re-checks them over time. So when you choose a certified provider, you are not just trusting that they are careful; you are inheriting the assurance of an audit you did not have to run. Paired with per-device certificates and a documented chain of custody, an ISO 27001-certified process gives a business the strongest practical footing for demonstrating that its retired data was handled to a recognised, independently verified standard. ITC's certifications are set out on our certifications page.
The questions businesses ask most about the standard and disposal.
Yes, through Annex A control 7.14, secure disposal or re-use of equipment, which requires equipment containing storage media to be verified as having its sensitive data removed or securely overwritten before disposal or reuse. Secure disposal is therefore a required control for an organisation certified to the standard, not an optional extra, and it must be able to demonstrate the control is in place.
It is the specific control in ISO 27001:2022 that addresses end-of-life equipment. It requires that items containing storage media be verified to ensure sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use. The key word is verified: the control is not met by attempting to remove the data, but by confirming it has been removed, which is why a per-device certificate matters.
Because it gives you independently verified evidence of the provider's information security controls, including disposal. Your own obligations, under the Privacy Act and, for financial institutions, APRA CPS 234, expect you to assess the capability of parties handling your data. A certificate from an independent body is objective evidence for that assessment, far stronger than a provider's own assurance.
No. An organisation can align its practices with ISO 27001 without being certified. Certification means an independent body has audited the organisation's information security management system and issued a certificate, maintained through ongoing surveillance. For a business relying on a provider to help meet its own obligations, certification is the stronger position, because it is externally verified rather than self-declared.
Yes. ITC is certified to ISO 27001:2022 for information security management, alongside certifications for environmental management, quality management, and health and safety. For disposal, the ISO 27001:2022 certification is the relevant one, because it independently verifies the information security controls, including secure disposal, that a business is expected to assess in a provider handling its data.
They work at different levels. ISO 27001 sets the management-system requirement that data be verified as removed before disposal or reuse. NIST 800-88 is a technical standard for how that removal is actually done, its Clear, Purge and Destroy levels. In practice, a provider certified to ISO 27001 meets the Annex A 7.14 control by destroying data to a recognised technical standard such as NIST 800-88 and verifying the result.
See how ITC's ISO 27001:2022-certified process meets the secure-disposal control, verifying and certifying the destruction of data on every device, so your own compliance rests on independent evidence.
Evidence for your auditor
Regulators do not ask whether you recycled the hardware. They ask what happened to the data on it, who handled it, and where the record is. ITC holds ISO/IEC 27001:2022 for information security alongside ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and issues serialised documentation on every job so the answer is already written down.