ISO 27001A.5 — Protection of records
A.5.33
Protection of records
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Protect records from loss, destruction, falsification, unauthorized access, and unauthorized release.
Points of focus
- Record types identified
- Retention and protection rules
- Integrity and access controls
- Disposal when retention ends
Implementation notes
List critical records: policies, risk results, SoA, internal audit, management review, incident records, training completion. Store in access-controlled systems with versioning. Back up per A.8.13 themes. Dispose per schedule and privacy needs (link A.5.34/A.8.10). Prefer systems of record over slide decks as sole evidence.
Audit tip: Show where last Stage 2 evidence pack lives, who can edit it, and retention.
Evidence auditors typically request:
- Records retention schedule for ISMS artifacts
- Access-controlled document repository
- Backup of critical records
- Disposal tickets for expired records
Common gaps
- ISMS docs only on a laptop
- Anyone can edit past audit evidence
- Retention forever 'just in case'
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.33 | This control |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.33)
Frequently Asked Questions
If decisions only live in chat, you have a record-keeping gap — promote decisions into tickets or controlled docs.
Follow your retention schedule and certification-body expectations; many teams keep at least one full cycle.
A.8.15 is technical logging; A.5.33 covers broader business/ISMS records including documents.