NIST SP 800-53 Rev 5
SI - System and Information Integrity

NIST SP 800-53 Rev 5 NIST800-SI-12: SI-12 Information Management and Retention

Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 57 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

  • CIS-3.1 Establish and Maintain a Data Management Process
  • CIS-3.2 Establish and Maintain a Data Inventory
  • CIS-3.4 Enforce Data Retention
  • CIS-8.10 Retain Audit Logs

ISO 27701:2019 · 4 controls

  • 7.4.7 Retention
  • 7.4.8 Disposal
  • 8.2.6 Records related to processing PII
  • 8.4.2 Return, transfer or disposal of PII

PCI DSS 4.0 · 4 controls

  • 10.5.1 10.5.1 Keep logs 12 months, latest three months online
  • 9.4.7 9.4.7 Destruction of electronic media
  • 3.2.1 3.2.1 Data retention and disposal minimise stored account data
  • 3.3.1 3.3.1 SAD not retained after authorization, even encrypted

SOC 2 · 4 controls

  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-PI1.1 PI1.1 Quality information about processing objectives, data definitions and specifications
  • ASBv3-GS-3 Define and implement data protection strategy
  • ASBv3-LT-6 Configure log storage retention
  • BR-1 Ensure regular automated backups
  • NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

APPI · 2 controls

  • APPI-A22 Accuracy and Deletion of Personal Data
  • APPI-A35 Request for Cessation of Use, Erasure or Cessation of Third Party Provision
  • AUCDR-IS-3 Securely manage information assets over their lifecycle
  • AUCDR-PS-12 Privacy Safeguard 12 - Security of CDR data and destruction or de-identification of redundant CDR data

C5 (Germany) · 2 controls

  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept
  • C5-PI-03 Secure deletion of data

GDPR · 2 controls

  • GDPR-Art.17 Right to erasure (right to be forgotten)
  • GDPR-Art.5 Principles relating to processing of personal data

ISO 27001:2022 · 2 controls

  • 5.33 Protection of records
  • 8.10 Information deletion

ISO 27002:2022 · 2 controls

  • 5.33 Protection of records
  • 8.10 Information deletion
  • CPS230-19 Tolerance Levels for Each Critical Operation
  • SEC07-BP04 Define scalable data lifecycle management
  • MYHR-GOV-5 Retention, destruction and correction obligations of the System Operator
  • AEO-3 Satisfactory System for Management of Commercial Records
  • CFTC-SS-20 Production of System Safeguards Books and Records

DORA · 1 control

EU AI Act · 1 control

FedRAMP High · 1 control

  • SI-12 Information Management and Retention

FedRAMP Moderate · 1 control

  • SI-12 Information Management and Retention

HIPAA Security Rule · 1 control

  • 03.14.08 Information Management and Retention

NIST SP 800-172 · 1 control

  • 3.14.5e Review Persistent Storage and Remove CUI No Longer Needed

NIST SP 800-187 · 1 control

NIST SP 800-218 · 1 control

  • SI-12 SI-12 Information Management and Retention
  • SI-12 SI-12 Information Management and Retention
  • SI-12 SI-12 Information Management and Retention

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SI - System and Information Integrity

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-SI-12 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 57 it maps to, and the evidence behind each claim, over MCP and REST.