ISO 27001:2022 Annex A 5.33 Protection of Records Explained

In this guide you will learn how to implement ISO 27001 Annex A 5.33 Protection of Records and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 5.33 Protection of Records is an ISO 27001 control that wants you to protect records in line with legal, regulatory, statutory and contractual requirements as well as societal and community expectations.

Purpose & Definition

The purpose of ISO 27001 Annex A 5.33 Protection of Records is to ensure you comply with legal, statutory, regulatory and contractual requirements related to the protection and availability of records.

Organisations should have a clear understanding of their obligations when it comes to the protection of records and make sure that they adhere to those requirements.

The ISO 27001 standard defines ISO 27001 Annex A 5.33 Protection of Records as:

Records should be protected from loss, destruction, falsification, unauthorised access and unauthorised release.

ISO/IEC 27001:2022 Annex A 5.33 Protection Of Records

FREE ISO 27001 Annex A 5.33 Training Video

In this free training video you will learn How to implement ISO 27001 Protection of Records (Annex A 5.33) and Pass Your Audit.

Implementation Guide

Decide what kinds of protection are included

The kinds of protection expected include protecting the authenticity, reliability, integrity and usability of records. You will consider this protection in the context of the business and its requirements and how that changes over time.

Decide what kind of records are included

Records is just another term for the data and information an organisation retains and/or uses to carry out its day to day business activities. It can include

  1. Individual events
  2. Transactions
  3. Work processes
  4. Activities
  5. Functions

You can manage any set of information as a record, irrespective of either its structure or its form.

Issue Guidelines

Guidelines on how you store, transfer and dispose of records will be issued.

Records Management Policy

You are going to implement an ISO 27001 Documents and Records Policy.

Retention Schedule

A retention schedule for records will be implemented that sets out how long you retain records.

Legislation

Where you operate and the legislation that applies to you as recorded in your ISO 27001 legal register and covered in ISO 27001 Annex A 5.31 Legal, regulatory, statutory and contractual requirements.

Record Destruction

You will implement procedures that destroy records in a safe and appropriate manner the moment they’re not needed and / or after the end of the retention period defined in the retention schedule.

Classification

Following your information classification and handling policy and your classification scheme you will apply that to records.

Retrieval times

You will make sure that any storage procedures and process include an acceptable timeframe for retrieval. These will also take into account and third party or external requests for records.

Encryption

Where encryption is implemented as a control to mitigate risk you will, of course, ensure that they keys to decrypt are available. Consider the guidance in ISO27001 Annex A 8.24 Use of Cryptography.

Manufacture Guidelines

You will follow the guidelines from the suppliers and manufacturers for storage and handling and you will take into account the possibility of media deteriorating over time.

Meta Data

The data that describes a record, its context, structure and other attributes is referred to as meta data and is seen as an essential component of any record.

How to implement ISO 27001 Annex 5.33

Implementing ISO 27001 Annex A 5.33 ensures your organisation safeguards its most critical information from loss, destruction, and unauthorised access. As an ISO 27001 Lead Auditor, I expect to see a lifecycle approach to data: from the moment a record is created to its final, secure destruction. Follow these ten technical steps to formalise your record protection framework and satisfy rigorous audit requirements.

1. Formalise a Topic-Specific Policy on Protection of Records

Formalise a mandatory policy that defines the organisation’s requirements for record identification, classification, and storage: this ensures a clear legal and operational baseline is established across the workforce.

  • Identify the specific legal, regulatory, and contractual requirements for record retention.
  • Define clear roles and responsibilities for record owners and custodians.
  • Document the consequences for policy violations to ensure staff accountability.

2. Provision a Detailed Record Inventory within the Asset Register

Provision the Asset Register to include specific entries for all critical records, whether physical or digital: this provides the visibility needed to apply appropriate technical and administrative controls.

  • Identify the “Owner” for every category of record documented.
  • Record the location of records, including cloud storage buckets, local file shares, or physical archives.
  • Link record assets to your broader ISMS risk assessment process.

3. Categorise Records by Security Classification and Sensitivity

Categorise all identified records according to the organisation’s information classification scheme: this ensures that security efforts are prioritised for high-value or highly sensitive data.

  • Apply labels to digital records via metadata or file-naming conventions.
  • Label physical record containers or storage areas clearly to prevent accidental disclosure.
  • Define the specific protection requirements (e.g., encryption, fireproofing) for each classification level.

4. Provision Secure Storage Environments for Physical Records

Provision physical storage areas that protect paper-based records from environmental hazards and unauthorised access: this ensures the physical integrity of non-digital information assets.

  • Deploy fire-resistant cabinets and water-leak detection systems in archive rooms.
  • Restrict physical access to record storage areas using keycards or biometric locks.
  • Implement a “Clean Desk” policy to ensure sensitive records are not left unattended in open offices.

5. Implement Role-Based Access Control via IAM

Implement strict Identity and Access Management (IAM) roles to limit access to digital record repositories: this ensures that only authorised personnel can view or modify sensitive information.

  • Apply the principle of least privilege to file servers, databases, and document management systems.
  • Mandate Multi-Factor Authentication (MFA) for all administrative or privileged access to record stores.
  • Review access logs monthly to identify any anomalous behaviour surrounding sensitive records.

6. Provision Automated Retention and Disposal Schedules

Provision automated systems or formal procedures to manage the lifecycle of records according to legal retention periods: this prevents the storage of unnecessary data and reduces legal liability.

  • Configure “Auto-Delete” or “Archive” rules for cloud storage and email systems based on data age.
  • Document a formal retention schedule that maps record types to specific statutory timeframes.
  • Perform quarterly reviews of stored data to identify records that have reached their end-of-life.

7. Implement Cryptographic Protections for Records at Rest and In Transit

Implement encryption for all records classified as sensitive or confidential: this ensures that data remains unreadable even if the underlying storage media is compromised.

  • Enforce full-disk encryption for laptops and mobile devices containing company records.
  • Use TLS 1.2 or higher for the transmission of records across public networks.
  • Manage cryptographic keys securely within a dedicated Key Management System (KMS).

8. Provision Redundant Backup and Recovery Systems

Provision secure backup procedures to ensure the availability of records in the event of technical failure or disaster: this ensures the organisation can recover critical information within defined timeframes.

  • Automate daily backups of all digital record repositories to a secure, off-site location.
  • Test record recovery procedures semi-annually to verify the integrity of backup data.
  • Protect backups with the same level of encryption and access control as production records.

Review the record protection framework against changing legal requirements, such as GDPR or sector-specific regulations: this ensures the ISMS remains aligned with external statutory obligations.

  • Consult with legal counsel to verify that retention periods meet current local laws.
  • Update the Record Protection Policy whenever new regulations are enacted.
  • Audit third-party supplier contracts to ensure they adhere to your record protection standards.

10. Audit the Effectiveness of Record Protections Regularly

Audit your record protection controls through the internal audit programme to verify ongoing compliance: this provides the final assurance needed for a successful ISO 27001 certification audit.

  • Test a sample of records to verify they are classified, stored, and retained correctly.
  • Review logs of record disposal to ensure destruction was performed securely and witnessed where required.
  • Document all findings in the Corrective Action Log to drive continuous ISMS improvement.

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

ISO 27001 Templates

ISO 27001 Templates - ISO 27001 Annex A 5.33 Protection of Records Templates
ISO 27001 Templates

ISO 27001 Annex A 5.33 FAQ

Is a record retention schedule mandatory for ISO 27001?

Yes, a formal record retention schedule is a core requirement for ISO 27001 compliance to demonstrate that the organisation manages the lifecycle of its data effectively.
The schedule must define what records are kept and for how long.
It must cite the specific legal or business justification for each retention period.
It serves as evidence for auditors that data is not kept longer than necessary, supporting GDPR compliance.
It must include instructions for the secure disposal of records once the retention period expires.

What is the difference between a document and a record?

The primary difference is that a document is a “live” file that can be edited or updated (such as a policy), whereas a record is historical evidence of an activity that has already occurred and must not be altered.
Documents provide instructions; records provide proof of execution.
Records are static and require “write-once-read-many” (WORM) style protection to prevent falsification.
Common records include audit logs, training certificates, signed contracts, and incident reports.

How should electronic records be protected from falsification?

Electronic records must be protected using technical controls such as digital signatures, hashing, and strict access permissions to ensure their integrity and authenticity over time.
Utilise Role-Based Access Control (RBAC) to ensure only authorised personnel can view archived records.
Implement audit logging to track every instance of access or attempted modification of a record.
Use cryptographic hashing to verify that a record has not been altered since it was originally saved.
Maintain regular backups and verify their restorability to prevent loss or destruction.

How long must ISO 27001 records be retained?

ISO 27001 does not specify a single retention period; instead, it requires organisations to define periods based on specific legal, regulatory, and contractual obligations.
Financial records are typically kept for 6 or 7 years to satisfy HMRC and tax laws.
Personnel records may have varying periods based on local employment legislation.
Contracts and agreements often require retention for the duration of the relationship plus a statutory limitation period (usually 6 years).
Technical logs may have shorter periods (e.g., 90 days or 1 year) depending on the organisation’s risk appetite.

What are the requirements for the secure disposal of records?

Records must be disposed of using methods that ensure the information is irrecoverable, thereby protecting the confidentiality of the data even after its lifecycle has ended.
Physical records should be shredded (cross-cut) or incinerated by a certified provider.
Digital records must be securely deleted or overwritten using industry-standard sanitisation methods.
Disposal activities should be documented to maintain a clear audit trail of the record’s destruction.
Storage media (hard drives, tapes) must be physically destroyed or cryptographically erased before being recycled.

ISO 27001 Annex A 5.12 Classification Of Information

Further Reading

ISO 27001 Controls and Attribute values

Control typeInformation security propertiesCybersecurity conceptsOperational capabilitiesSecurity domains
PreventiveAvailabilityIdentifyLegal and complianceDefence
IntegrityProtectAsset management
ConfidentialityInformation protection

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top