Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.7.10 Storage Media

Storage Media Lifecycle Controls

Our media management framework maps across four distinct lifecycle stages:

1. Acquisition

  • Procurement Authority: Hardware and media assets are acquired based on the specific operational requirements of an individual's role. The configuration and technical specifications must be approved by the Operations Manager and/or the Director.
  • Financial Integrity: All procurement workflows must strictly adhere to the formalized controls outlined in anDREa Internal Control Framework (AO/IC & P&C) guidelines.

2. Use

  • Operational Baselines: The day-to-day handling, software configurations, full-disk encryption mandates, and patch requirements for active storage media must fully comply with A.06.07: Remote Working.

3. Transportation

  • Removable Media Restrictions: Physical data transport using USB flash drives or external hard drives is prohibited. Personnel must natively utilize secure, cloud-based transfer methods (such as Google Drive or explicit myDRE environments) or encrypted wireless peer-to-peer protocols (e.g., QuickShare).
  • Exception Handling: If a physical USB drive must be used due to a total lack of network alternatives, the drive must be fully encrypted in alignment with the guidelines in A.05.12: Classification of Information and A.05.13: Labelling of Information. Unencrypted transport of non-public data is strictly banned.

4. Disposal

  • Sanitization Requirements: When storage media reaches its end of life, is decommissioned, or is prepared for a new user, it must be completely sanitized or physically destroyed to ensure that data cannot be recovered. This process is governed under A.07.14: Secure Disposal or Re-Use of Equipment and the overarching Retention & Destruction Policy.

Administration & Cross-References