N.3.08 Safely dispose of or reuse company equipment
Control Overview
This control mandates that the organization establishes and implements formal technical and operational procedures for the secure decommissioning, disposal, or reuse of company equipment containing built-in storage media (e.g., laptops, tablets, mobile phones, external hard drives). To prevent unauthorized data exposure, regulatory non-compliance, or licensing liabilities, all sensitive corporate data and proprietary software must be definitively erased, cryptographically wiped, or physically destroyed before a device leaves the organization's control or is re-allocated to another user.
Applicability Note: This control is fully applicable to the anDREa platform and governs the entire hardware lifecycle of endpoints issued to our remote workforce.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, turning hardware lifecycle adjustments into a tightly monitored, multi-step verification process.
Because anDREa operates under a fully remote model, hardware transitions present an elevated risk of data residual leakage. To mitigate this, our Remote Working framework dictates that employees cannot independently retire, sell, or reuse company-issued assets. When a device reaches its end-of-life or an employee changes hardware, the transaction must be explicitly routed through the Security Officer. The endpoint must undergo a verifiable cryptographic or factory wipe managed via our Central Mobile Device Management (MDM) platform, rendering past data unrecoverable. Once complete, the deletion is formalized and logged, creating a clean audit trail before the asset can be safely recycled, returned to a vendor, or destroyed.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.07.14 - Secure disposal or re-use of equipment | Mandates that items of equipment containing storage media are verified to ensure that any sensitive data and licensed software have been removed or securely overwritten prior to disposal or re-use. |
| ISO/IEC 27001 | A.06.07 - Remote working | Extends hardware replacement, return, and decommissioning security rules to off-site corporate endpoints. |
| Operational Governance | Hardware Lifecycle & Remote Working Policy | The authoritative text specifying user obligations, device collection steps, and the explicit ban on unverified asset disposal. (A.05.11 - Return of assets) |
| Technical Verification | Security Officer Decommissioning Logs | Signed verification histories and system-generated certificates confirming the successful technical wipe of endpoints. (A.05.11 - Return of assets) |
| MDM Configurations | Remote Wipe Execution Records | System event receipts from Intune or Google Admin proving that data sanitization commands were successfully pushed and acknowledged by retired endpoints. (A.08.01 - User end point devices) |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. The framework for hardware lifecycle monitoring, mandatory Security Officer verification, and automated data-wiping triggers is fully operationalized.
- Continuous Improvement: To provide extra forensic assurance during upcoming compliance audits, explicitly document the specific sanitization standards (e.g., NIST SP 800-88 Rev. 1 "Guidelines for Media Sanitization") or native cryptographic erasure mechanisms leveraged by your MDM platforms within the policy text.