Skip to content
compliancebase
ISO 27001A.5 — Protection of records

A.5.33

Protection of records

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Protect records from loss, destruction, falsification, unauthorized access, and unauthorized release.

Points of focus

  • Record types identified
  • Retention and protection rules
  • Integrity and access controls
  • Disposal when retention ends

Implementation notes

List critical records: policies, risk results, SoA, internal audit, management review, incident records, training completion. Store in access-controlled systems with versioning. Back up per A.8.13 themes. Dispose per schedule and privacy needs (link A.5.34/A.8.10). Prefer systems of record over slide decks as sole evidence.

Audit tip: Show where last Stage 2 evidence pack lives, who can edit it, and retention.

Evidence auditors typically request:

  • Records retention schedule for ISMS artifacts
  • Access-controlled document repository
  • Backup of critical records
  • Disposal tickets for expired records

Common gaps

  • ISMS docs only on a laptop
  • Anyone can edit past audit evidence
  • Retention forever 'just in case'

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.33This control

Primary sources

Frequently Asked Questions

If decisions only live in chat, you have a record-keeping gap — promote decisions into tickets or controlled docs.

Follow your retention schedule and certification-body expectations; many teams keep at least one full cycle.

A.8.15 is technical logging; A.5.33 covers broader business/ISMS records including documents.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above