ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 2. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 5.33 Protection of records

ISO 27001 Annex A 5.33 Protection of records

What is ISO 27001 Annex A 5.33 – Protection of Records?

ISO 27001 Annex A 5.33 requires an organization to protect records from loss, destruction, falsification, unauthorized access, and unauthorized release, in accordance with applicable legal, regulatory, contractual, and business requirements.

In simple terms:

Important records should remain available, accurate, trustworthy, protected, and accessible only to authorized people for as long as they need to be retained.

Records may include:

  • Contracts
  • Customer records
  • Audit reports
  • Financial records
  • HR records
  • Security logs
  • Incident records
  • Compliance records
  • Meeting records
  • Approval records
  • System records
  • Business transactions
  • Legal records
  • Security assessment reports
  • Backup and recovery records

A record is different from ordinary information because it may need to be retained as evidence of an activity, decision, transaction, obligation, or event.


Why is A.5.33 Important?

Organizations create large amounts of information every day.

But not all information needs to be retained indefinitely.

Some records must be protected because they may be needed to:

  • Demonstrate compliance
  • Prove a transaction occurred
  • Support legal requirements
  • Demonstrate an audit trail
  • Investigate incidents
  • Support customer obligations
  • Demonstrate management decisions
  • Meet contractual requirements
  • Support financial reporting
  • Preserve business history

If important records are deleted, altered, leaked, or become unavailable, the organization may not be able to demonstrate what happened.

Simple Principle

“If a record is important enough to keep, it is important enough to protect.”


What is a Record?

A record is information retained as evidence of an activity, transaction, decision, obligation, or event.

Examples

Security

  • Security incident report
  • Vulnerability assessment report
  • Access review
  • Risk assessment
  • Audit report

Business

  • Customer contract
  • Purchase order
  • Invoice
  • Approval record
  • Business transaction

HR

  • Employment record
  • Training record
  • Disciplinary record
  • Employee acknowledgment

Compliance

  • Compliance assessment
  • Management review
  • Corrective action
  • Certification record

Technology

  • System logs
  • Backup records
  • Change records
  • Configuration records

Record vs. Information

Not every piece of information is necessarily a formal record.

For example:

InformationRecord?
Temporary chat messageUsually not
Draft documentUsually not
Final signed contractYes
Final audit reportYes
Approved security policyYes
Temporary working notesUsually not
Security incident reportYes
Final customer invoiceYes
Approved risk assessmentYes

The organization should define what constitutes a record based on its business and compliance requirements.


What Does A.5.33 Require?

The organization should determine how records will be:

  1. Identified
  2. Classified
  3. Stored
  4. Protected
  5. Accessed
  6. Retained
  7. Retrieved
  8. Preserved
  9. Disposed of

The organization should consider risks such as:

  • Unauthorized modification
  • Unauthorized deletion
  • Accidental deletion
  • Loss
  • Corruption
  • Unauthorized disclosure
  • Ransomware
  • Hardware failure
  • Cloud failure
  • Insider threats
  • Legal disputes
  • Inadequate retention
  • Excessive retention

Activities Required to Implement A.5.33

1. Identify Important Records

Start by identifying records that are important to the organization.

For example:

  • Customer contracts
  • Financial records
  • Employee records
  • Security records
  • Compliance records
  • Audit reports
  • Incident records
  • Legal documents
  • Business continuity records

Avoid creating an enormous list of every file in the organization.

Focus on records that require formal protection or retention.


2. Create a Records Register

A practical organization can maintain a records register.

Example:

RecordOwnerClassificationRetentionStorageDisposal
Customer contractsLegalConfidentialContractual periodDocument systemSecure deletion
Audit reportsComplianceConfidentialDefined periodCompliance repositoryControlled deletion
Security incident reportsSecurityConfidentialDefined periodRestricted repositoryControlled deletion
Employee recordsHRConfidentialLegal requirementHR systemControlled deletion
Financial recordsFinanceConfidentialApplicable requirementFinance systemControlled deletion

3. Define Retention Periods

Different records may need different retention periods.

Retention may be determined by:

  • Law
  • Regulation
  • Contract
  • Business requirements
  • Legal requirements
  • Litigation holds
  • Industry requirements

For example:

RecordExample Retention
Customer contractContract period + required period
Security incident recordDefined security retention period
Financial recordApplicable legal requirement
Employee recordApplicable employment requirement
Audit evidenceCertification/audit requirement

The exact retention period should be determined based on the applicable requirements rather than using one universal period.


4. Protect Records From Unauthorized Modification

Important records should not be freely editable.

Controls may include:

  • Role-based access
  • Read-only access
  • Approval workflows
  • Version control
  • Audit trails
  • Digital signatures
  • Document management controls
  • Restricted repositories

For example:

A final SOC 2 report should not be stored in a location where every employee can modify it.


5. Protect Records From Unauthorized Deletion

Critical records should have appropriate protection against accidental or malicious deletion.

Possible measures include:

  • Restricted delete permissions
  • Retention locks
  • Version history
  • Immutable storage
  • Backup
  • Legal hold
  • Approval for deletion

The appropriate control depends on the nature and importance of the record.


6. Protect Records From Unauthorized Disclosure

Records may contain:

  • Personal information
  • Customer information
  • Financial information
  • Security information
  • Confidential business information

Therefore, access should be restricted based on business need.

For example:

Employee records → HR

Financial records → Finance

Security incident records → Security/authorized management

Customer contracts → Legal/authorized business teams


7. Ensure Records Remain Available

Protection does not only mean confidentiality.

Records should remain available when legitimately required.

Consider:

  • Backups
  • Redundant storage
  • Cloud availability
  • Disaster recovery
  • Document management
  • Access recovery
  • Business continuity

A critical record that cannot be retrieved when needed can create significant operational and compliance problems.


8. Maintain Integrity

The organization should be able to trust that a record has not been improperly changed.

Depending on the type of record, this can be supported through:

  • Access controls
  • Version history
  • Audit logs
  • Approval workflows
  • Digital signatures
  • Hashing
  • Immutable storage

The level of protection should be appropriate to the record’s importance and risk.


9. Establish Record Disposal

Retention does not mean:

“Keep everything forever.”

Organizations should determine when records can be securely disposed of.

Disposal methods may include:

  • Secure deletion
  • Controlled destruction
  • Media destruction
  • Cryptographic erasure
  • Secure disposal by approved providers

Before disposal, the organization should consider whether:

  • A legal hold exists
  • A contract requires continued retention
  • An audit is ongoing
  • An investigation is ongoing
  • Regulatory retention applies

10. Protect Records During Legal or Regulatory Events

Certain situations may require records to be preserved beyond their normal retention period.

Examples:

  • Litigation
  • Regulatory investigation
  • Security investigation
  • Customer dispute
  • Internal investigation

A legal hold or equivalent preservation process may be required.


Startup Example

Consider a SaaS startup preparing for ISO 27001 certification.

The organization maintains:

  • Customer contracts
  • Security policies
  • Risk assessments
  • Audit reports
  • Incident reports
  • Access reviews
  • VAPT reports
  • Employee training records
  • Management review records

The startup creates a records register.

Example

ISO 27001 Audit Report

↓

Classification: Confidential

↓

Owner: Compliance

↓

Storage: Restricted compliance repository

↓

Access: Compliance + authorized management

↓

Retention: Defined according to business/certification requirements

↓

Backup: Protected backup

↓

Deletion: Controlled disposal after retention period

This provides a structured way of protecting important records.


Startup-Focused Quick Summary

A startup does not need a complex enterprise records-management platform to implement A.5.33.

A practical approach is:

1. Identify

What records are important?

2. Classify

How sensitive are they?

3. Assign Ownership

Who is responsible?

4. Store

Where should they be maintained?

5. Protect

Who can access, modify or delete them?

6. Retain

How long should they be kept?

7. Retrieve

Can authorized users find them when needed?

8. Dispose

How are they securely destroyed when no longer required?

Simple Model

Identify → Classify → Store → Protect → Retain → Retrieve → Dispose


Example Records Register

IDRecordOwnerClassificationRetentionAccessStorage
REC-001Customer contractsLegalConfidentialDefined contractual periodLegal/ManagementDocument repository
REC-002Security incident reportsSecurityHighly ConfidentialDefined periodSecurity/ManagementRestricted repository
REC-003Risk assessmentsComplianceConfidentialISMS retention periodCompliance/ManagementISMS repository
REC-004Audit reportsComplianceConfidentialDefined periodCompliance/ManagementCompliance repository
REC-005Employee training recordsHRConfidentialApplicable requirementHRHR system
REC-006Financial recordsFinanceConfidentialApplicable requirementFinanceFinance system

Record Protection Matrix

RiskExample Control
Unauthorized accessRBAC
Unauthorized modificationRead-only/version control
Unauthorized deletionRestricted deletion
Accidental deletionBackup
RansomwareProtected/immutable backup
Data leakageEncryption/access control
Record corruptionBackup/versioning
Loss of availabilityRedundant storage
TamperingAudit logs/integrity controls
Excessive retentionRetention schedule
Premature disposalRetention controls/legal hold

Audit Evidence for A.5.33

An auditor may request:

Governance

  • Records Management Policy
  • Records Retention Policy
  • Information Classification Policy

Registers

  • Records Register
  • Retention Schedule
  • Information Asset Register

Protection

  • Access control configuration
  • Document repository permissions
  • Version history
  • Audit logs
  • Backup configuration

Retention

  • Retention schedules
  • Record retention reviews
  • Legal hold records

Disposal

  • Secure deletion records
  • Media destruction records
  • Disposal approvals
  • Disposal certificates where applicable

Examples

An auditor may select sample records and ask:

“Show me how this record is protected, who can access it, how long it is retained, and what happens when the retention period expires.”


A.5.33 Audit Checklist

Audit QuestionEvidence
Has the organization identified important records?Records register
Are record owners assigned?Records register
Are records classified?Classification records
Are retention requirements defined?Retention schedule
Are records protected against unauthorized access?Access controls
Are records protected against unauthorized modification?Versioning/access controls
Are deletion rights restricted?Permissions
Are critical records backed up?Backup evidence
Can records be retrieved when needed?Retrieval evidence
Are records protected from unauthorized disclosure?Access controls
Are disposal requirements defined?Disposal procedure
Is secure disposal performed?Disposal evidence
Are legal holds considered?Legal hold records
Are retention requirements periodically reviewed?Review evidence

Common Mistakes

1. Keeping Everything Forever

More data does not automatically mean better records management.

Excessive retention can create:

  • Storage costs
  • Privacy risks
  • Security risks
  • Discovery burden
  • Compliance concerns

The organization should retain records according to applicable requirements and legitimate business needs.


2. No Retention Schedule

If employees decide individually how long to keep records, retention becomes inconsistent.


3. Everyone Can Modify Important Records

Critical records should have appropriate access restrictions.


4. Backups Are Treated as the Records Policy

A backup protects availability and recovery.

It does not by itself define:

  • Which records must be retained
  • How long they must be retained
  • Who may access them
  • When they should be deleted

5. No Protection Against Deletion

A user with excessive permissions may accidentally or intentionally delete important records.


6. Storing Records in Personal Accounts

Important organizational records should not depend on personal:

  • Gmail accounts
  • Personal cloud drives
  • Personal computers
  • Personal storage

7. No Legal Hold Process

Records may need to be preserved beyond normal retention periods when a legal or regulatory matter arises.


8. No Evidence of Disposal

An organization may have a retention policy but no evidence showing that disposal is actually performed.


Practical Startup Implementation Model

A startup can implement A.5.33 using this sequence:

Step 1 – Identify

Identify records that need formal protection.

Step 2 – Classify

Determine their sensitivity.

Step 3 – Assign

Assign an owner.

Step 4 – Store

Use approved organizational repositories.

Step 5 – Protect

Apply access, integrity and availability controls.

Step 6 – Retain

Define appropriate retention periods.

Step 7 – Review

Periodically review retention and access.

Step 8 – Dispose

Securely dispose of records when permitted.

Simple Model

Identify → Classify → Assign → Store → Protect → Retain → Review → Dispose


Policy vs. Process vs. Evidence

TypeExample
PolicyRecords Management Policy
PolicyRecords Retention Policy
ProcessRecords Retention Procedure
ProcessSecure Records Disposal Procedure
ProcessLegal Hold Procedure
DocumentRecords Register
DocumentRetention Schedule
EvidenceAccess review
EvidenceRepository audit log
EvidenceBackup record
EvidenceRetention review
EvidenceDisposal record

Remember

Policy = What records must be protected

Process = How records are managed

Register = Which records exist and how they are handled

Evidence = Proof that records are actually protected


Relationship With Other ISO 27001 Controls

A.5.33 is closely connected with several controls.

ControlRelationship
A.5.9 Inventory of Information and Other Associated AssetsHelps identify information and assets containing records
A.5.10 Acceptable UseDefines appropriate use of information and assets
A.5.12 Classification of InformationHelps determine appropriate protection
A.5.13 Labelling of InformationSupports identification and handling of sensitive records
A.5.15 Access ControlRestricts access to records
A.5.18 Access RightsManages who can access records
A.5.31 Legal/Regulatory/Contractual RequirementsIdentifies retention and protection obligations
A.5.32 Intellectual Property RightsProtects records containing intellectual property
A.5.34 Privacy and Protection of PIIApplies to records containing personal information
A.8.10 Information DeletionSupports appropriate deletion of information
A.8.13 Information BackupSupports availability and recovery
A.8.15 LoggingProtects and provides evidence of activities
A.8.17 Clock SynchronizationSupports reliable time-related records and logs

Useful Documents for A.5.33

  • Records Management Policy – [Insert Draft Document Link]
  • Records Retention Policy – [Insert Draft Document Link]
  • Records Register – [Insert Draft Document Link]
  • Records Retention Schedule – [Insert Draft Document Link]
  • Secure Records Disposal Procedure – [Insert Draft Document Link]
  • Legal Hold Procedure – [Insert Draft Document Link]
  • Records Access Review Checklist – [Insert Draft Document Link]
  • Records Management Audit Checklist – [Insert Draft Document Link]

Questions an Auditor May Ask

Identification

  • What records are considered important to your organization?
  • How did you determine which records require protection?
  • Where are these records stored?

Protection

  • Who can access these records?
  • Who can modify or delete them?
  • How do you prevent unauthorized changes?

Retention

  • How long do you retain this record?
  • How was the retention period determined?
  • What happens when the retention period expires?

Availability

  • How would you recover an important record if it were accidentally deleted?
  • Are critical records backed up?

Disposal

  • How are records securely disposed of?
  • Who approves disposal?
  • How do you ensure records subject to legal hold are not deleted?

Startup-Focused Final Takeaway

ISO 27001 Annex A 5.33 is about making sure that important organizational records remain:

Available

Accurate

Protected

Traceable

Retained for the required period

Accessible only to authorized people

For a startup, this does not require a complicated enterprise records-management system.

The organization should simply be able to answer:

What records do we need to keep?

Why do we need to keep them?

Where are they stored?

Who can access or modify them?

How long do we retain them?

How do we protect them from loss, alteration or unauthorized disclosure?

How do we securely dispose of them when they are no longer required?

Practical Implementation Flow

Identify Records

↓

Classify

↓

Assign Ownership

↓

Store in Approved Repository

↓

Protect Access & Integrity

↓

Define Retention

↓

Review

↓

Secure Disposal

The practical auditor question is:

“Show me how your organization identifies, protects, retains, retrieves, and securely disposes of important records, and demonstrate that those records cannot be improperly accessed, altered, lost, or destroyed.”

That is the practical objective of ISO 27001 Annex A 5.33 – Protection of Records.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *