A.5.33A.5 Organizational controls

Protection of records

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.33 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Protect records from loss, destruction, falsification, unauthorised access and unauthorised release.

How to meet this control

In short: Protect records from loss, destruction, falsification and unauthorised access.

  1. Step 01Define a records retention schedule by record type aligned to legal and regulatory requirements
  2. Step 02Apply access controls, encryption and backups to protect key records from loss, falsification and unauthorised access
  3. Step 03Choose storage that allows timely retrieval in an acceptable format and guards against technology obsolescence
  4. Step 04Retain cryptographic keys and software needed to read archived or signed records
  5. Step 05Securely destroy records once retention expires and log the destruction

Tip: Set retention schedules and use access controls plus backups for key records.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Issue guidelines on storing, handling, chain of custody and disposing of records
  • ›Draw up a retention schedule defining which records to keep and for how long
  • ›Align retention periods with national and regional laws, allowing proper destruction afterward
  • ›Classify records by type and assign retention periods and allowable storage media to each
  • ›Choose storage systems that let records be retrieved in an acceptable time and format
  • ›Maintain access to records over the full retention period, guarding against technology obsolescence
  • ›Retain cryptographic keys and programs needed to decrypt archived or signed records
  • ›Follow media manufacturer recommendations and account for media deterioration over time

Audit evidence to keep

  • - Records retention schedule mapping record types to retention periods
  • - Evidence of access controls and backups protecting key records
  • - Records of secure destruction once retention expires
  • - Evidence that archived records remain retrievable over their retention period

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.5.33. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.