Why it matters
Data recovered from improperly wiped hardware is a well-documented real-world breach source.
How a self-led small team implements it
A certified wipe (or physical destruction) step before any device is resold, recycled, or returned is the concrete fix.
What auditors expect to see
Disposal/wipe certificates.
Track A.7.14 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS