In this guide you will learn how to implement ISO 27001 Annex A 5.33 Protection of Records and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.33 Protection of Records is an ISO 27001 control that wants you to protect records in line with legal, regulatory, statutory and contractual requirements as well as societal and community expectations.
Table of contents
Purpose & Definition
The purpose of ISO 27001 Annex A 5.33 Protection of Records is to ensure you comply with legal, statutory, regulatory and contractual requirements related to the protection and availability of records.
Organisations should have a clear understanding of their obligations when it comes to the protection of records and make sure that they adhere to those requirements.
The ISO 27001 standard defines ISO 27001 Annex A 5.33 Protection of Records as:
Records should be protected from loss, destruction, falsification, unauthorised access and unauthorised release.
ISO 27001:2022 Annex A 5.33
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.33 Training Video
In this free training video you will learn How to implement ISO 27001 Protection of Records (Annex A 5.33) and Pass Your Audit.
Implementation Guide
Decide what kinds of protection are included
The kinds of protection expected include protecting the authenticity, reliability, integrity and usability of records. You will consider this protection in the context of the business and its requirements and how that changes over time.
Decide what kind of records are included
Records is just another term for the data and information an organisation retains and/or uses to carry out its day to day business activities. It can include
- Individual events
- Transactions
- Work processes
- Activities
- Functions
You can manage any set of information as a record, irrespective of either its structure or its form.
Issue Guidelines
Guidelines on how you store, transfer and dispose of records will be issued.
Records Management Policy
You are going to implement an ISO 27001 Documents and Records Policy.
Retention Schedule
A retention schedule for records will be implemented that sets out how long you retain records.
Legislation
Where you operate and the legislation that applies to you as recorded in your ISO 27001 legal register and covered in ISO 27001 Annex A 5.31 Legal, regulatory, statutory and contractual requirements.
Record Destruction
You will implement procedures that destroy records in a safe and appropriate manner the moment they’re not needed and / or after the end of the retention period defined in the retention schedule.
Classification
Following your information classification and handling policy and your classification scheme you will apply that to records.
Retrieval times
You will make sure that any storage procedures and process include an acceptable timeframe for retrieval. These will also take into account and third party or external requests for records.
Encryption
Where encryption is implemented as a control to mitigate risk you will, of course, ensure that they keys to decrypt are available. Consider the guidance in ISO27001 Annex A 8.24 Use of Cryptography.
Manufacture Guidelines
You will follow the guidelines from the suppliers and manufacturers for storage and handling and you will take into account the possibility of media deteriorating over time.
Meta Data
The data that describes a record, its context, structure and other attributes is referred to as meta data and is seen as an essential component of any record.
How to implement ISO 27001 Annex 5.33
Implementing ISO 27001 Annex A 5.33 ensures your organisation safeguards its most critical information from loss, destruction, and unauthorised access. As an ISO 27001 Lead Auditor, I expect to see a lifecycle approach to data: from the moment a record is created to its final, secure destruction. Follow these ten technical steps to formalise your record protection framework and satisfy rigorous audit requirements.
1. Formalise a Topic-Specific Policy on Protection of Records
Formalise a mandatory policy that defines the organisation’s requirements for record identification, classification, and storage: this ensures a clear legal and operational baseline is established across the workforce.
- Identify the specific legal, regulatory, and contractual requirements for record retention.
- Define clear roles and responsibilities for record owners and custodians.
- Document the consequences for policy violations to ensure staff accountability.
2. Provision a Detailed Record Inventory within the Asset Register
Provision the Asset Register to include specific entries for all critical records, whether physical or digital: this provides the visibility needed to apply appropriate technical and administrative controls.
- Identify the “Owner” for every category of record documented.
- Record the location of records, including cloud storage buckets, local file shares, or physical archives.
- Link record assets to your broader ISMS risk assessment process.
3. Categorise Records by Security Classification and Sensitivity
Categorise all identified records according to the organisation’s information classification scheme: this ensures that security efforts are prioritised for high-value or highly sensitive data.
- Apply labels to digital records via metadata or file-naming conventions.
- Label physical record containers or storage areas clearly to prevent accidental disclosure.
- Define the specific protection requirements (e.g., encryption, fireproofing) for each classification level.
4. Provision Secure Storage Environments for Physical Records
Provision physical storage areas that protect paper-based records from environmental hazards and unauthorised access: this ensures the physical integrity of non-digital information assets.
- Deploy fire-resistant cabinets and water-leak detection systems in archive rooms.
- Restrict physical access to record storage areas using keycards or biometric locks.
- Implement a “Clean Desk” policy to ensure sensitive records are not left unattended in open offices.
5. Implement Role-Based Access Control via IAM
Implement strict Identity and Access Management (IAM) roles to limit access to digital record repositories: this ensures that only authorised personnel can view or modify sensitive information.
- Apply the principle of least privilege to file servers, databases, and document management systems.
- Mandate Multi-Factor Authentication (MFA) for all administrative or privileged access to record stores.
- Review access logs monthly to identify any anomalous behaviour surrounding sensitive records.
6. Provision Automated Retention and Disposal Schedules
Provision automated systems or formal procedures to manage the lifecycle of records according to legal retention periods: this prevents the storage of unnecessary data and reduces legal liability.
- Configure “Auto-Delete” or “Archive” rules for cloud storage and email systems based on data age.
- Document a formal retention schedule that maps record types to specific statutory timeframes.
- Perform quarterly reviews of stored data to identify records that have reached their end-of-life.
7. Implement Cryptographic Protections for Records at Rest and In Transit
Implement encryption for all records classified as sensitive or confidential: this ensures that data remains unreadable even if the underlying storage media is compromised.
- Enforce full-disk encryption for laptops and mobile devices containing company records.
- Use TLS 1.2 or higher for the transmission of records across public networks.
- Manage cryptographic keys securely within a dedicated Key Management System (KMS).
8. Provision Redundant Backup and Recovery Systems
Provision secure backup procedures to ensure the availability of records in the event of technical failure or disaster: this ensures the organisation can recover critical information within defined timeframes.
- Automate daily backups of all digital record repositories to a secure, off-site location.
- Test record recovery procedures semi-annually to verify the integrity of backup data.
- Protect backups with the same level of encryption and access control as production records.
9. Review Legal, Regulatory, and Contractual Compliance Regularly
Review the record protection framework against changing legal requirements, such as GDPR or sector-specific regulations: this ensures the ISMS remains aligned with external statutory obligations.
- Consult with legal counsel to verify that retention periods meet current local laws.
- Update the Record Protection Policy whenever new regulations are enacted.
- Audit third-party supplier contracts to ensure they adhere to your record protection standards.
10. Audit the Effectiveness of Record Protections Regularly
Audit your record protection controls through the internal audit programme to verify ongoing compliance: this provides the final assurance needed for a successful ISO 27001 certification audit.
- Test a sample of records to verify they are classified, stored, and retained correctly.
- Review logs of record disposal to ensure destruction was performed securely and witnessed where required.
- Document all findings in the Corrective Action Log to drive continuous ISMS improvement.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

ISO 27001 Templates

How to Audit ISO 27001 Annex A 5.33
Auditing ISO 27001 Annex A 5.33 requires a technical deep dive into how your organisation identifies, classifies, and safeguards its critical data throughout its lifecycle. As a Lead Auditor, I am looking for evidence that goes beyond a simple policy: I want to see technical asset mapping, encryption configurations, and airtight retention schedules. Use this 10 step technical roadmap to ensure your record protection controls are robust enough to withstand a certification audit.
1. Audit the Records Retention and Protection Policy
Audit the topic-specific policy for record protection to confirm it defines the organisation’s approach to safeguarding internal data and respecting third-party privacy: result: establishes the legal and procedural baseline for the entire ISMS.
- Verify that the policy explicitly covers retention periods for financial, legal, and operational records.
- Check for clear definitions of record types and their required protection levels.
- Confirm the policy is reviewed annually and signed off by senior management.
2. Inspect the Asset Register for Record Mapping
Inspect the Asset Register to ensure that all critical records and data stores are identified and classified: result: provides the visibility required to apply granular security controls to high-value information.
- Review the register for entries including databases, physical archives, and cloud storage buckets.
- Verify that an “Asset Owner” is assigned to every category of protected records.
- Check that the classification levels, such as Highly Confidential, align with the sensitivity of the data.
3. Review Encryption Standards for Electronic Records
Review the technical configuration for records at rest and in transit to verify that encryption meets industry standards: result: ensures the confidentiality and integrity of electronic records against unauthorised access.
- Compare technical settings against the organisation’s encryption policy requirements.
- Audit key management procedures to ensure cryptographic keys are stored securely.
- Verify that TLS 1.2 or higher is enforced for all data transmission involving sensitive records.
4. Audit IAM Roles for Record Repositories
Audit Identity and Access Management (IAM) roles for all file servers, databases, and document management systems: result: ensures that access to core records follows the principle of least privilege.
- Inspect access control lists (ACLs) for platforms such as SharePoint, AWS S3, or local file shares.
- Verify that users only have access to the specific record sets required for their current roles.
- Audit the process for revoking access to record repositories within 24 hours of staff departure.
5. Provision MFA for Record Access Points
Verify that Multi-Factor Authentication (MFA) is mandated for every technical interface that hosts or manages protected records: result: provides a critical defensive layer against credential theft and unauthorised data release.
- Check configuration settings on cloud storage, ERP systems, and backup consoles.
- Ensure MFA is enforced for all administrative accounts and privileged users.
- Review logs for any instances where MFA was bypassed or disabled.
6. Examine Physical Security for Paper Records
Examine the physical environment where paper-based records are stored to confirm protection against environmental threats and theft: result: ensures the availability and integrity of physical information assets.
- Inspect the use of fire-resistant cabinets and water-leak detection in archive rooms.
- Verify that physical access to record storage areas is logged and restricted via keycards or locks.
- Check for “Clean Desk” compliance to ensure sensitive records are not left unattended.
7. Audit Backup and Disaster Recovery Procedures
Audit the backup logs and recovery test results for all critical record repositories: result: confirms the availability of records in the event of technical failure or a ransomware attack.
- Verify that backups are performed according to the frequency defined in the ISMS.
- Check for evidence of periodic restoration tests to prove record recoverability.
- Inspect the security of off-site or cloud-based backup storage to ensure it is isolated from the production network.
8. Inspect Legal and Regulatory Compliance Clauses
Examine a sample of contracts and legal requirements to ensure records are maintained in accordance with statutory obligations: result: confirms that the organisation is not at risk of legal penalties for premature record destruction.
- Verify compliance with jurisdiction-specific laws such as GDPR, HIPAA, or local Companies Acts.
- Check for “Legal Hold” procedures that prevent the deletion of records during litigation.
- Review the Rules of Engagement (ROE) for third-party storage providers to ensure data sovereignty.
9. Audit Secure Disposal and Destruction Logs
Audit the disposal logs for decommissioned hardware and shredded physical records to ensure data is destroyed securely: result: prevents the accidental disclosure of protected records via legacy media.
- Verify certificates of destruction for all physical disks and confidential waste.
- Check that cloud-based storage volumes were securely wiped before being released.
- Inspect the Asset Register to ensure disposed assets are formally decommissioned.
10. Audit Records of Access and Modification
Audit the audit logs and file integrity monitoring records to verify that record modifications are authorised: result: provides evidence that the organisation maintains a reliable audit trail for its protected information.
- Review the logs for any reports of unauthorised attempts to modify or delete records.
- Verify that log files themselves are protected from tampering or unauthorised deletion.
- Check for evidence of regular log reviews being conducted by the security team.
ISO 27001 Annex A 5.33 FAQ
Yes, a formal record retention schedule is a core requirement for ISO 27001 compliance to demonstrate that the organisation manages the lifecycle of its data effectively.
The schedule must define what records are kept and for how long.
It must cite the specific legal or business justification for each retention period.
It serves as evidence for auditors that data is not kept longer than necessary, supporting GDPR compliance.
It must include instructions for the secure disposal of records once the retention period expires.
The primary difference is that a document is a “live” file that can be edited or updated (such as a policy), whereas a record is historical evidence of an activity that has already occurred and must not be altered.
Documents provide instructions; records provide proof of execution.
Records are static and require “write-once-read-many” (WORM) style protection to prevent falsification.
Common records include audit logs, training certificates, signed contracts, and incident reports.
Electronic records must be protected using technical controls such as digital signatures, hashing, and strict access permissions to ensure their integrity and authenticity over time.
Utilise Role-Based Access Control (RBAC) to ensure only authorised personnel can view archived records.
Implement audit logging to track every instance of access or attempted modification of a record.
Use cryptographic hashing to verify that a record has not been altered since it was originally saved.
Maintain regular backups and verify their restorability to prevent loss or destruction.
ISO 27001 does not specify a single retention period; instead, it requires organisations to define periods based on specific legal, regulatory, and contractual obligations.
Financial records are typically kept for 6 or 7 years to satisfy HMRC and tax laws.
Personnel records may have varying periods based on local employment legislation.
Contracts and agreements often require retention for the duration of the relationship plus a statutory limitation period (usually 6 years).
Technical logs may have shorter periods (e.g., 90 days or 1 year) depending on the organisation’s risk appetite.
Records must be disposed of using methods that ensure the information is irrecoverable, thereby protecting the confidentiality of the data even after its lifecycle has ended.
Physical records should be shredded (cross-cut) or incinerated by a certified provider.
Digital records must be securely deleted or overwritten using industry-standard sanitisation methods.
Disposal activities should be documented to maintain a clear audit trail of the record’s destruction.
Storage media (hard drives, tapes) must be physically destroyed or cryptographically erased before being recycled.
Related ISO 27001 Controls
ISO 27001 Annex A 5.12 Classification Of Information
Further Reading
- ISO 27001 Data Retention Policy Beginner’s Guide
- ISO 27001 Data Protection Policy Template
- Data Retention Policy Template
- ISO 27001 Information Classification and Handling Policy Beginner’s Guide
ISO 27001 Controls and Attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Availability | Identify | Legal and compliance | Defence |
| Integrity | Protect | Asset management | ||
| Confidentiality | Information protection |
