Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.33

Protection of Records: A Practical Implementation Guide

Keep records authentic, available, confidential and usable for as long as the organization needs them.

This control concerns protecting records from loss, destruction, falsification, unauthorized access and unauthorized release.

Practical interpretation: Records are evidence of business activity and obligations. Protection must cover retention, integrity, access, retrieval, format and defensible disposal.

What should the control achieve?

  • Record categories and retention requirements are known.
  • Integrity and access match record value.
  • Records remain readable and retrievable.
  • Disposal is authorized and suspended by legal holds.

Step-by-step implementation

1

Define record classes

Identify operational, financial, HR, security, legal and customer records.

2

Set retention rules

Base periods and triggers on law, contract, business and limitation needs.

3

Assign owners and repositories

Use approved systems with suitable metadata and access.

4

Protect integrity

Apply immutability, versioning, signatures, checksums or audit logs as needed.

5

Ensure retrieval

Test search, export, backup and format readability.

6

Dispose defensibly

Authorize deletion, record evidence and honor legal holds.

What this could look like in practice

Security incident records are retained in a restricted case system for a defined period. Audit logs are immutable, exports are tested annually and legal holds prevent deletion during disputes.

ActivityPractical implementationEvidence
Record creationRequired metadata and owner are captured.Repository record
RetentionRules calculate disposal date from event trigger.Retention configuration
Legal holdDeletion is suspended for scoped records.Hold notice
DisposalApproved batch deletion produces evidence.Disposal certificate

Implementation evidence

  • Records policy
  • Retention schedule
  • Repository inventory
  • Access controls
  • Integrity settings
  • Retrieval tests
  • Legal-hold records
  • Disposal logs

Useful metrics

  • Records with assigned retention
  • Overdue disposal
  • Failed retrieval tests
  • Unauthorized record access

Common mistakes

  • Keeping everything forever.
  • Using creation date when another trigger applies.
  • Storing official records in personal mailboxes.
  • No format-migration plan.
  • Deleting records subject to hold.

Questions an auditor may ask

  • Which records are critical?
  • How are retention periods determined?
  • Show an integrity or retrieval test.
  • How are legal holds enforced?
Implementation test: Request an older critical record and prove timely retrieval, authenticity, authorized access and correct retention status.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.