ISO/IEC 27001:2022 Annex A · Control 5.33
Protection of Records: A Practical Implementation Guide
Keep records authentic, available, confidential and usable for as long as the organization needs them.
This control concerns protecting records from loss, destruction, falsification, unauthorized access and unauthorized release.
What should the control achieve?
- Record categories and retention requirements are known.
- Integrity and access match record value.
- Records remain readable and retrievable.
- Disposal is authorized and suspended by legal holds.
Step-by-step implementation
Define record classes
Identify operational, financial, HR, security, legal and customer records.
Set retention rules
Base periods and triggers on law, contract, business and limitation needs.
Assign owners and repositories
Use approved systems with suitable metadata and access.
Protect integrity
Apply immutability, versioning, signatures, checksums or audit logs as needed.
Ensure retrieval
Test search, export, backup and format readability.
Dispose defensibly
Authorize deletion, record evidence and honor legal holds.
What this could look like in practice
Security incident records are retained in a restricted case system for a defined period. Audit logs are immutable, exports are tested annually and legal holds prevent deletion during disputes.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Record creation | Required metadata and owner are captured. | Repository record |
| Retention | Rules calculate disposal date from event trigger. | Retention configuration |
| Legal hold | Deletion is suspended for scoped records. | Hold notice |
| Disposal | Approved batch deletion produces evidence. | Disposal certificate |
Implementation evidence
- Records policy
- Retention schedule
- Repository inventory
- Access controls
- Integrity settings
- Retrieval tests
- Legal-hold records
- Disposal logs
Useful metrics
- Records with assigned retention
- Overdue disposal
- Failed retrieval tests
- Unauthorized record access
Common mistakes
- Keeping everything forever.
- Using creation date when another trigger applies.
- Storing official records in personal mailboxes.
- No format-migration plan.
- Deleting records subject to hold.
Questions an auditor may ask
- Which records are critical?
- How are retention periods determined?
- Show an integrity or retrieval test.
- How are legal holds enforced?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.