Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Director

previous version on gdrive

N.3.08 Safely dispose of or reuse company equipment

Control Overview

This control mandates that the organization establishes and implements formal technical and operational procedures for the secure decommissioning, disposal, or reuse of company equipment containing built-in storage media (e.g., laptops, tablets, mobile phones, external hard drives). To prevent unauthorized data exposure, regulatory non-compliance, or licensing liabilities, all sensitive corporate data and proprietary software must be definitively erased, cryptographically wiped, or physically destroyed before a device leaves the organization's control or is re-allocated to another user.

Applicability Note: This control is fully applicable to the anDREa platform and governs the entire hardware lifecycle of endpoints issued to our remote workforce.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, turning hardware lifecycle adjustments into a tightly monitored, multi-step verification process.

Because anDREa operates under a fully remote model, hardware transitions present an elevated risk of data residual leakage. To mitigate this, our Remote Working framework dictates that employees cannot independently retire, sell, or reuse company-issued assets. When a device reaches its end-of-life or an employee changes hardware, the transaction must be explicitly routed through the Security Officer. The endpoint must undergo a verifiable cryptographic or factory wipe managed via our Central Mobile Device Management (MDM) platform, rendering past data unrecoverable. Once complete, the deletion is formalized and logged, creating a clean audit trail before the asset can be safely recycled, returned to a vendor, or destroyed.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.07.14 - Secure disposal or re-use of equipmentMandates that items of equipment containing storage media are verified to ensure that any sensitive data and licensed software have been removed or securely overwritten prior to disposal or re-use.
ISO/IEC 27001A.06.07 - Remote workingExtends hardware replacement, return, and decommissioning security rules to off-site corporate endpoints.
Operational GovernanceHardware Lifecycle & Remote Working PolicyThe authoritative text specifying user obligations, device collection steps, and the explicit ban on unverified asset disposal. (A.05.11 - Return of assets)
Technical VerificationSecurity Officer Decommissioning LogsSigned verification histories and system-generated certificates confirming the successful technical wipe of endpoints. (A.05.11 - Return of assets)
MDM ConfigurationsRemote Wipe Execution RecordsSystem event receipts from Intune or Google Admin proving that data sanitization commands were successfully pushed and acknowledged by retired endpoints. (A.08.01 - User end point devices)

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. The framework for hardware lifecycle monitoring, mandatory Security Officer verification, and automated data-wiping triggers is fully operationalized.
  • Continuous Improvement: To provide extra forensic assurance during upcoming compliance audits, explicitly document the specific sanitization standards (e.g., NIST SP 800-88 Rev. 1 "Guidelines for Media Sanitization") or native cryptographic erasure mechanisms leveraged by your MDM platforms within the policy text.