Maintaining compliance under **ISO/IEC 27001:2022 (Control A.8.10 & A.8.14)** requires not only storage drive sanitization, but also resetting hardware security silicon (**TPM 2.0**), clearing cryptographic certificates in BIOS/UEFI firmware, and revoking machine identities.
1. TPM 2.0 Reset & BitLocker Key Revocation
Trusted Platform Module (TPM 2.0) chips store hardware Endorsement Keys, enterprise computer identity certs, and Platform Configuration Register (PCR) measurements. Failing to clear TPM silicon exposes enterprise identity payloads upon hardware transfer.
🔐 ISO 27001 Audit Checklist:
- Clear TPM Hierarchy: Execute Clear-TPM via OS or UEFI firmware menu.
- Restore Factory Secure Boot Keys: Reset PK/KEK/db certificate databases to factory default.
- Clear Biometric Enclaves & Intel AMT: Reset Intel vPro / AMT out-of-band management engines.
2. Supply Chain Security & Hardware Passports
ISO 27001 auditors mandate verified Chain of Custody records. SpecInfo v20 generates cryptographically signed PDF technical passports, streamlining annual compliance audits.