Records are to be safeguarded against being lost, destroyed, falsified, accessed without authorization or released without authorization. Purpose: meet legal, regulatory and contractual obligations and community or societal expectations about keeping records protected and available. Guidance: so records stay genuine, trustworthy, complete and usable as their business context and management needs evolve, issue guidelines on storing and handling records, chain of custody and disposal, including preventing tampering, aligned with the records management policy; and prepare a retention schedule naming records and how long each is kept. The storage and handling arrangements should identify records and their retention periods with regard to national or regional law and, where relevant, societal expectations, and allow proper destruction once a record is no longer needed. Protection of particular records takes account of their classification. Records are grouped into types (for example accounting, transaction, personnel, legal), each with its retention period and the physical or electronic media allowed. Storage systems are chosen so that records come back quickly enough and in a usable format. For electronic media, procedures keep records accessible and readable for the whole retention period despite technology change, and the keys and programs for encrypted archives or digital signatures are kept for as long as the records (8.24). Storage and handling follow media manufacturers' recommendations and allow for media deterioration. Other information: records evidence events, transactions or processes and are information assets in any form; metadata describing their context, content, structure and management is essential; law may fix retention periods and content; ISO 15489 covers records management.
This control maps to 87 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 5.33 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.