Protection of records
Purpose
Protect records from loss, destruction, falsification, unauthorised access and unauthorised release.
How to meet this control
In short: Protect records from loss, destruction, falsification and unauthorised access.
- Step 01Define a records retention schedule by record type aligned to legal and regulatory requirements
- Step 02Apply access controls, encryption and backups to protect key records from loss, falsification and unauthorised access
- Step 03Choose storage that allows timely retrieval in an acceptable format and guards against technology obsolescence
- Step 04Retain cryptographic keys and software needed to read archived or signed records
- Step 05Securely destroy records once retention expires and log the destruction
Tip: Set retention schedules and use access controls plus backups for key records.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Issue guidelines on storing, handling, chain of custody and disposing of records
- ›Draw up a retention schedule defining which records to keep and for how long
- ›Align retention periods with national and regional laws, allowing proper destruction afterward
- ›Classify records by type and assign retention periods and allowable storage media to each
- ›Choose storage systems that let records be retrieved in an acceptable time and format
- ›Maintain access to records over the full retention period, guarding against technology obsolescence
- ›Retain cryptographic keys and programs needed to decrypt archived or signed records
- ›Follow media manufacturer recommendations and account for media deterioration over time
Audit evidence to keep
- - Records retention schedule mapping record types to retention periods
- - Evidence of access controls and backups protecting key records
- - Records of secure destruction once retention expires
- - Evidence that archived records remain retrievable over their retention period
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.5.33. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.