What is ISO 27001 Annex A 5.33 – Protection of Records?
ISO 27001 Annex A 5.33 requires an organization to protect records from loss, destruction, falsification, unauthorized access, and unauthorized release, in accordance with applicable legal, regulatory, contractual, and business requirements.
In simple terms:
Important records should remain available, accurate, trustworthy, protected, and accessible only to authorized people for as long as they need to be retained.
Records may include:
- Contracts
- Customer records
- Audit reports
- Financial records
- HR records
- Security logs
- Incident records
- Compliance records
- Meeting records
- Approval records
- System records
- Business transactions
- Legal records
- Security assessment reports
- Backup and recovery records
A record is different from ordinary information because it may need to be retained as evidence of an activity, decision, transaction, obligation, or event.
Why is A.5.33 Important?
Organizations create large amounts of information every day.
But not all information needs to be retained indefinitely.
Some records must be protected because they may be needed to:
- Demonstrate compliance
- Prove a transaction occurred
- Support legal requirements
- Demonstrate an audit trail
- Investigate incidents
- Support customer obligations
- Demonstrate management decisions
- Meet contractual requirements
- Support financial reporting
- Preserve business history
If important records are deleted, altered, leaked, or become unavailable, the organization may not be able to demonstrate what happened.
Simple Principle
“If a record is important enough to keep, it is important enough to protect.”
What is a Record?
A record is information retained as evidence of an activity, transaction, decision, obligation, or event.
Examples
Security
- Security incident report
- Vulnerability assessment report
- Access review
- Risk assessment
- Audit report
Business
- Customer contract
- Purchase order
- Invoice
- Approval record
- Business transaction
HR
- Employment record
- Training record
- Disciplinary record
- Employee acknowledgment
Compliance
- Compliance assessment
- Management review
- Corrective action
- Certification record
Technology
- System logs
- Backup records
- Change records
- Configuration records
Record vs. Information
Not every piece of information is necessarily a formal record.
For example:
| Information | Record? |
|---|---|
| Temporary chat message | Usually not |
| Draft document | Usually not |
| Final signed contract | Yes |
| Final audit report | Yes |
| Approved security policy | Yes |
| Temporary working notes | Usually not |
| Security incident report | Yes |
| Final customer invoice | Yes |
| Approved risk assessment | Yes |
The organization should define what constitutes a record based on its business and compliance requirements.
What Does A.5.33 Require?
The organization should determine how records will be:
- Identified
- Classified
- Stored
- Protected
- Accessed
- Retained
- Retrieved
- Preserved
- Disposed of
The organization should consider risks such as:
- Unauthorized modification
- Unauthorized deletion
- Accidental deletion
- Loss
- Corruption
- Unauthorized disclosure
- Ransomware
- Hardware failure
- Cloud failure
- Insider threats
- Legal disputes
- Inadequate retention
- Excessive retention
Activities Required to Implement A.5.33
1. Identify Important Records
Start by identifying records that are important to the organization.
For example:
- Customer contracts
- Financial records
- Employee records
- Security records
- Compliance records
- Audit reports
- Incident records
- Legal documents
- Business continuity records
Avoid creating an enormous list of every file in the organization.
Focus on records that require formal protection or retention.
2. Create a Records Register
A practical organization can maintain a records register.
Example:
| Record | Owner | Classification | Retention | Storage | Disposal |
|---|---|---|---|---|---|
| Customer contracts | Legal | Confidential | Contractual period | Document system | Secure deletion |
| Audit reports | Compliance | Confidential | Defined period | Compliance repository | Controlled deletion |
| Security incident reports | Security | Confidential | Defined period | Restricted repository | Controlled deletion |
| Employee records | HR | Confidential | Legal requirement | HR system | Controlled deletion |
| Financial records | Finance | Confidential | Applicable requirement | Finance system | Controlled deletion |
3. Define Retention Periods
Different records may need different retention periods.
Retention may be determined by:
- Law
- Regulation
- Contract
- Business requirements
- Legal requirements
- Litigation holds
- Industry requirements
For example:
| Record | Example Retention |
|---|---|
| Customer contract | Contract period + required period |
| Security incident record | Defined security retention period |
| Financial record | Applicable legal requirement |
| Employee record | Applicable employment requirement |
| Audit evidence | Certification/audit requirement |
The exact retention period should be determined based on the applicable requirements rather than using one universal period.
4. Protect Records From Unauthorized Modification
Important records should not be freely editable.
Controls may include:
- Role-based access
- Read-only access
- Approval workflows
- Version control
- Audit trails
- Digital signatures
- Document management controls
- Restricted repositories
For example:
A final SOC 2 report should not be stored in a location where every employee can modify it.
5. Protect Records From Unauthorized Deletion
Critical records should have appropriate protection against accidental or malicious deletion.
Possible measures include:
- Restricted delete permissions
- Retention locks
- Version history
- Immutable storage
- Backup
- Legal hold
- Approval for deletion
The appropriate control depends on the nature and importance of the record.
6. Protect Records From Unauthorized Disclosure
Records may contain:
- Personal information
- Customer information
- Financial information
- Security information
- Confidential business information
Therefore, access should be restricted based on business need.
For example:
Employee records → HR
Financial records → Finance
Security incident records → Security/authorized management
Customer contracts → Legal/authorized business teams
7. Ensure Records Remain Available
Protection does not only mean confidentiality.
Records should remain available when legitimately required.
Consider:
- Backups
- Redundant storage
- Cloud availability
- Disaster recovery
- Document management
- Access recovery
- Business continuity
A critical record that cannot be retrieved when needed can create significant operational and compliance problems.
8. Maintain Integrity
The organization should be able to trust that a record has not been improperly changed.
Depending on the type of record, this can be supported through:
- Access controls
- Version history
- Audit logs
- Approval workflows
- Digital signatures
- Hashing
- Immutable storage
The level of protection should be appropriate to the record’s importance and risk.
9. Establish Record Disposal
Retention does not mean:
“Keep everything forever.”
Organizations should determine when records can be securely disposed of.
Disposal methods may include:
- Secure deletion
- Controlled destruction
- Media destruction
- Cryptographic erasure
- Secure disposal by approved providers
Before disposal, the organization should consider whether:
- A legal hold exists
- A contract requires continued retention
- An audit is ongoing
- An investigation is ongoing
- Regulatory retention applies
10. Protect Records During Legal or Regulatory Events
Certain situations may require records to be preserved beyond their normal retention period.
Examples:
- Litigation
- Regulatory investigation
- Security investigation
- Customer dispute
- Internal investigation
A legal hold or equivalent preservation process may be required.
Startup Example
Consider a SaaS startup preparing for ISO 27001 certification.
The organization maintains:
- Customer contracts
- Security policies
- Risk assessments
- Audit reports
- Incident reports
- Access reviews
- VAPT reports
- Employee training records
- Management review records
The startup creates a records register.
Example
ISO 27001 Audit Report
↓
Classification: Confidential
↓
Owner: Compliance
↓
Storage: Restricted compliance repository
↓
Access: Compliance + authorized management
↓
Retention: Defined according to business/certification requirements
↓
Backup: Protected backup
↓
Deletion: Controlled disposal after retention period
This provides a structured way of protecting important records.
Startup-Focused Quick Summary
A startup does not need a complex enterprise records-management platform to implement A.5.33.
A practical approach is:
1. Identify
What records are important?
2. Classify
How sensitive are they?
3. Assign Ownership
Who is responsible?
4. Store
Where should they be maintained?
5. Protect
Who can access, modify or delete them?
6. Retain
How long should they be kept?
7. Retrieve
Can authorized users find them when needed?
8. Dispose
How are they securely destroyed when no longer required?
Simple Model
Identify → Classify → Store → Protect → Retain → Retrieve → Dispose
Example Records Register
| ID | Record | Owner | Classification | Retention | Access | Storage |
|---|---|---|---|---|---|---|
| REC-001 | Customer contracts | Legal | Confidential | Defined contractual period | Legal/Management | Document repository |
| REC-002 | Security incident reports | Security | Highly Confidential | Defined period | Security/Management | Restricted repository |
| REC-003 | Risk assessments | Compliance | Confidential | ISMS retention period | Compliance/Management | ISMS repository |
| REC-004 | Audit reports | Compliance | Confidential | Defined period | Compliance/Management | Compliance repository |
| REC-005 | Employee training records | HR | Confidential | Applicable requirement | HR | HR system |
| REC-006 | Financial records | Finance | Confidential | Applicable requirement | Finance | Finance system |
Record Protection Matrix
| Risk | Example Control |
|---|---|
| Unauthorized access | RBAC |
| Unauthorized modification | Read-only/version control |
| Unauthorized deletion | Restricted deletion |
| Accidental deletion | Backup |
| Ransomware | Protected/immutable backup |
| Data leakage | Encryption/access control |
| Record corruption | Backup/versioning |
| Loss of availability | Redundant storage |
| Tampering | Audit logs/integrity controls |
| Excessive retention | Retention schedule |
| Premature disposal | Retention controls/legal hold |
Audit Evidence for A.5.33
An auditor may request:
Governance
- Records Management Policy
- Records Retention Policy
- Information Classification Policy
Registers
- Records Register
- Retention Schedule
- Information Asset Register
Protection
- Access control configuration
- Document repository permissions
- Version history
- Audit logs
- Backup configuration
Retention
- Retention schedules
- Record retention reviews
- Legal hold records
Disposal
- Secure deletion records
- Media destruction records
- Disposal approvals
- Disposal certificates where applicable
Examples
An auditor may select sample records and ask:
“Show me how this record is protected, who can access it, how long it is retained, and what happens when the retention period expires.”
A.5.33 Audit Checklist
| Audit Question | Evidence |
|---|---|
| Has the organization identified important records? | Records register |
| Are record owners assigned? | Records register |
| Are records classified? | Classification records |
| Are retention requirements defined? | Retention schedule |
| Are records protected against unauthorized access? | Access controls |
| Are records protected against unauthorized modification? | Versioning/access controls |
| Are deletion rights restricted? | Permissions |
| Are critical records backed up? | Backup evidence |
| Can records be retrieved when needed? | Retrieval evidence |
| Are records protected from unauthorized disclosure? | Access controls |
| Are disposal requirements defined? | Disposal procedure |
| Is secure disposal performed? | Disposal evidence |
| Are legal holds considered? | Legal hold records |
| Are retention requirements periodically reviewed? | Review evidence |
Common Mistakes
1. Keeping Everything Forever
More data does not automatically mean better records management.
Excessive retention can create:
- Storage costs
- Privacy risks
- Security risks
- Discovery burden
- Compliance concerns
The organization should retain records according to applicable requirements and legitimate business needs.
2. No Retention Schedule
If employees decide individually how long to keep records, retention becomes inconsistent.
3. Everyone Can Modify Important Records
Critical records should have appropriate access restrictions.
4. Backups Are Treated as the Records Policy
A backup protects availability and recovery.
It does not by itself define:
- Which records must be retained
- How long they must be retained
- Who may access them
- When they should be deleted
5. No Protection Against Deletion
A user with excessive permissions may accidentally or intentionally delete important records.
6. Storing Records in Personal Accounts
Important organizational records should not depend on personal:
- Gmail accounts
- Personal cloud drives
- Personal computers
- Personal storage
7. No Legal Hold Process
Records may need to be preserved beyond normal retention periods when a legal or regulatory matter arises.
8. No Evidence of Disposal
An organization may have a retention policy but no evidence showing that disposal is actually performed.
Practical Startup Implementation Model
A startup can implement A.5.33 using this sequence:
Step 1 – Identify
Identify records that need formal protection.
Step 2 – Classify
Determine their sensitivity.
Step 3 – Assign
Assign an owner.
Step 4 – Store
Use approved organizational repositories.
Step 5 – Protect
Apply access, integrity and availability controls.
Step 6 – Retain
Define appropriate retention periods.
Step 7 – Review
Periodically review retention and access.
Step 8 – Dispose
Securely dispose of records when permitted.
Simple Model
Identify → Classify → Assign → Store → Protect → Retain → Review → Dispose
Policy vs. Process vs. Evidence
| Type | Example |
|---|---|
| Policy | Records Management Policy |
| Policy | Records Retention Policy |
| Process | Records Retention Procedure |
| Process | Secure Records Disposal Procedure |
| Process | Legal Hold Procedure |
| Document | Records Register |
| Document | Retention Schedule |
| Evidence | Access review |
| Evidence | Repository audit log |
| Evidence | Backup record |
| Evidence | Retention review |
| Evidence | Disposal record |
Remember
Policy = What records must be protected
Process = How records are managed
Register = Which records exist and how they are handled
Evidence = Proof that records are actually protected
Relationship With Other ISO 27001 Controls
A.5.33 is closely connected with several controls.
| Control | Relationship |
|---|---|
| A.5.9 Inventory of Information and Other Associated Assets | Helps identify information and assets containing records |
| A.5.10 Acceptable Use | Defines appropriate use of information and assets |
| A.5.12 Classification of Information | Helps determine appropriate protection |
| A.5.13 Labelling of Information | Supports identification and handling of sensitive records |
| A.5.15 Access Control | Restricts access to records |
| A.5.18 Access Rights | Manages who can access records |
| A.5.31 Legal/Regulatory/Contractual Requirements | Identifies retention and protection obligations |
| A.5.32 Intellectual Property Rights | Protects records containing intellectual property |
| A.5.34 Privacy and Protection of PII | Applies to records containing personal information |
| A.8.10 Information Deletion | Supports appropriate deletion of information |
| A.8.13 Information Backup | Supports availability and recovery |
| A.8.15 Logging | Protects and provides evidence of activities |
| A.8.17 Clock Synchronization | Supports reliable time-related records and logs |
Useful Documents for A.5.33
- Records Management Policy – [Insert Draft Document Link]
- Records Retention Policy – [Insert Draft Document Link]
- Records Register – [Insert Draft Document Link]
- Records Retention Schedule – [Insert Draft Document Link]
- Secure Records Disposal Procedure – [Insert Draft Document Link]
- Legal Hold Procedure – [Insert Draft Document Link]
- Records Access Review Checklist – [Insert Draft Document Link]
- Records Management Audit Checklist – [Insert Draft Document Link]
Questions an Auditor May Ask
Identification
- What records are considered important to your organization?
- How did you determine which records require protection?
- Where are these records stored?
Protection
- Who can access these records?
- Who can modify or delete them?
- How do you prevent unauthorized changes?
Retention
- How long do you retain this record?
- How was the retention period determined?
- What happens when the retention period expires?
Availability
- How would you recover an important record if it were accidentally deleted?
- Are critical records backed up?
Disposal
- How are records securely disposed of?
- Who approves disposal?
- How do you ensure records subject to legal hold are not deleted?
Startup-Focused Final Takeaway
ISO 27001 Annex A 5.33 is about making sure that important organizational records remain:
Available
Accurate
Protected
Traceable
Retained for the required period
Accessible only to authorized people
For a startup, this does not require a complicated enterprise records-management system.
The organization should simply be able to answer:
What records do we need to keep?
Why do we need to keep them?
Where are they stored?
Who can access or modify them?
How long do we retain them?
How do we protect them from loss, alteration or unauthorized disclosure?
How do we securely dispose of them when they are no longer required?
Practical Implementation Flow
Identify Records
↓
Classify
↓
Assign Ownership
↓
Store in Approved Repository
↓
Protect Access & Integrity
↓
Define Retention
↓
Review
↓
Secure Disposal
The practical auditor question is:
“Show me how your organization identifies, protects, retains, retrieves, and securely disposes of important records, and demonstrate that those records cannot be improperly accessed, altered, lost, or destroyed.”
That is the practical objective of ISO 27001 Annex A 5.33 – Protection of Records.
