ISO 27001 information deletion (control 8.10)
ISO 27001 is about an information security management system — and one of its controls is simply: delete information when you're done with it.
ISO/IEC 27001:2022 addresses erasure through Annex A control 8.10, "Information deletion". It requires organisations to delete information when it's no longer needed, in a way that accounts for legal, statutory, regulatory, and contractual requirements.
What the control asks for
Unlike GDPR or HIPAA, ISO 27001 doesn't prescribe a technique — it prescribes a management system. Control 8.10 expects you to have a policy and procedure for deleting information, to apply it consistently, and to keep evidence that it happened. The supporting guidance points to sanitisation of media before disposal or reuse.
Where disk erasure fits
When the "information" in question lives on decommissioned storage, the deletion procedure is media sanitisation:
- Reuse — a Clear-level erase (overwrite, Secure Erase) before redeploying a drive.
- Disposal — a Purge-level erase (Enhanced Secure Erase, NVMe Sanitize, crypto erase) before a drive leaves the organisation.
- Destruction — for drives that can't be erased.
Evidence for the auditor
In an ISO 27001 audit, the question isn't "do you erase?" — it's "show me your last ten erasures." A chain-of-custody report tied to serial numbers, with a certificate of destruction you can produce on request, is exactly the kind of objective evidence an auditor wants to see. It turns a policy document into a demonstrated practice.
FAQ
Is ISO 27001 the same as GDPR?
No. ISO 27001 is a voluntary management-system certification; GDPR is law. They overlap — both demand verifiable deletion — but satisfying one doesn't automatically satisfy the other. A good erasure practice helps with both.
Do I need a certificate of destruction for ISO 27001?
It's not strictly mandated, but a verifiable certificate is the most efficient way to demonstrate control 8.10 in an audit.