ISO 27002:2022
Organizational controls – ISO 27002:2022

ISO 27002:2022 5.33: Protection of records

Records are to be safeguarded against being lost, destroyed, falsified, accessed without authorization or released without authorization. Purpose: meet legal, regulatory and contractual obligations and community or societal expectations about keeping records protected and available. Guidance: so records stay genuine, trustworthy, complete and usable as their business context and management needs evolve, issue guidelines on storing and handling records, chain of custody and disposal, including preventing tampering, aligned with the records management policy; and prepare a retention schedule naming records and how long each is kept. The storage and handling arrangements should identify records and their retention periods with regard to national or regional law and, where relevant, societal expectations, and allow proper destruction once a record is no longer needed. Protection of particular records takes account of their classification. Records are grouped into types (for example accounting, transaction, personnel, legal), each with its retention period and the physical or electronic media allowed. Storage systems are chosen so that records come back quickly enough and in a usable format. For electronic media, procedures keep records accessible and readable for the whole retention period despite technology change, and the keys and programs for encrypted archives or digital signatures are kept for as long as the records (8.24). Storage and handling follow media manufacturers' recommendations and allow for media deterioration. Other information: records evidence events, transactions or processes and are information assets in any form; metadata describing their context, content, structure and management is essential; law may fix retention periods and content; ISO 15489 covers records management.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 87 controls across 39 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 10 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-P6.2 P6.2 Record of authorised disclosures
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches
  • SOC2-PI1.5 PI1.5 Controls over stored inputs, work in process and outputs

ISO 27701:2019 · 6 controls

  • 6.9.3 Backup
  • 7.2.8 Records related to processing PII
  • 7.5.3 Records of transfer of PII
  • 7.5.4 Records of PII disclosure to third parties
  • 8.2.6 Records related to processing PII
  • 8.5.3 Records of PII disclosure to third parties

NIST SP 800-53 Rev 5 · 6 controls

PCI DSS 4.0 · 5 controls

  • 10.3.2 10.3.2 Audit log files protected from modification
  • 10.5.1 10.5.1 Keep logs 12 months, latest three months online
  • 3.3.3 3.3.3 Issuer SAD storage limited, justified and encrypted
  • 9.4.7 9.4.7 Destruction of electronic media
  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data

CIS Controls v8 · 4 controls

  • CIS-11.3 Protect Recovery Data
  • CIS-3.1 Establish and Maintain a Data Management Process
  • CIS-3.4 Enforce Data Retention
  • CIS-3.5 Securely Dispose of Data

ISO/IEC 42001:2023 · 4 controls

  • 7.5 Documented information
  • 7.5.3 Control of documented information
  • A.7.5 Data provenance
  • A.8 Information for interested parties of AI systems
  • ISM-1510 Digital preservation policy
  • ISM-1815 Protecting event logs from modification and deletion
  • ISM-1985 Protecting event logs from unauthorised access

FedRAMP High · 3 controls

  • AU-11 Audit Record Retention
  • AU-9 Protection of Audit Information
  • SI-12 Information Management and Retention

FedRAMP Moderate · 3 controls

  • AU-11 Audit Record Retention
  • AU-9 Protection of Audit Information
  • SI-12 Information Management and Retention

HIPAA Security Rule · 3 controls

  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

APPI · 2 controls

  • APPI-A29 Records When Providing Personal Data to a Third Party
  • APPI-A30 Confirmation and Records When Receiving Personal Data from a Third Party
  • ASBv3-LT-6 Configure log storage retention
  • BR-2 Protect backup and recovery data

ISO 22301:2019 · 2 controls

  • 7.5 Documented information
  • 7.5.3 Control of documented information

ISO 27001:2022 · 2 controls

  • 5.28 Collection of evidence
  • 5.33 Protection of records

NIST SP 800-171 Rev 3 · 2 controls

  • 03.03.08 Protection of Audit Information
  • 03.14.08 Information Management and Retention

NIST SP 800-66 Rev 2 · 2 controls

  • 0071 0071 Operational controls for information holdings proportional to value
  • 0074 0074 Destroy classified information when retention ends
  • E8-BACKUP-ML1 Regular Backups (ML1)
  • 44(1) s 44(1) Reasonable steps to protect surveillance records
  • A.3.1 A.3.1 Records demonstrating conformity and results
  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations
  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator
  • AEO-3 Satisfactory System for Management of Commercial Records

C5 (Germany) · 1 control

  • C5-OPS-12 Logging and Monitoring - Access, Storage and Deletion
  • CFTC-SS-37 Protection of Swap Data Repository Data

CMMC 2.0 · 1 control

DORA · 1 control

  • DORA-Art.12 Backup policies and procedures, restoration and recovery

GDPR · 1 control

  • GDPR-Art.5 Principles relating to processing of personal data

MTCS (Singapore) · 1 control

  • 13.5 Backup and retention of audit trails

NIS2 Directive · 1 control

  • Art.28 Maintain accurate domain name registration data and answer lawful access requests within 72 hours

NIST SP 800-218 · 1 control

  • s36 s 36 Secure storage of covert surveillance records
  • TSA-PSG-13 Recordkeeping and document control
  • MTSA-Recordkeeping Recordkeeping and Records Protection
  • EIDAS-Art.34 Qualified preservation service for qualified electronic signatures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 5.33 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 87 it maps to, and the evidence behind each claim, over MCP and REST.