Home / Rules / ISO/IEC 27001:2022 / ISO/IEC 27001:2022 Annex A 5.33 Protection of records
ISO/IEC 27001:2022 Annex A 5.33 Protection of records
Records are to be safeguarded against being lost, destroyed, falsified, accessed without authorization or released without authorization. Purpose (stated in ISO/IEC 27002:2022): ensures compliance with legal, regulatory and contractual obligations and societal expectations for protecting and keeping records available.
Steps that cite it
- KC-08 S2 What does the auditor get?
Evidence commonly asked for
- Statement of Applicability entry for control A.5.33, showing inclusion or justified exclusion, implementation status and the risks it treats
- Records handling guidelines covering storage, chain of custody, tamper prevention and disposal, aligned with the records management policy
- A retention schedule listing record types, retention periods, legal basis and permitted storage media
- Evidence of controlled destruction at the end of retention periods
Accepted citation forms are listed on the answer format page.