A.5.33 Organizational
Protection of records
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (12)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AU-11mostlyaligns with — Both controls mandate retention schedules and protection measures that ensure audit records remain authentic, unaltered, and retrievable for the required duration.
- SI-12mostlyaligns with — Both controls require organizations to define retention periods, storage methods, and destruction procedures that preserve the integrity and accessibility of records throughout their lifecycle.
- CM-2partialaligns with — Both controls require documented configurations for storage systems and media handling to ensure consistent, reliable access to retained records over time.
- MP-6partialaligns with — Both controls address the secure disposal of media or records once their retention period expires to prevent unauthorized access or manipulation.
- SC-28partialaligns with — Both controls require protection of stored information against loss of integrity or accessibility, including handling of encryption keys needed for long-term retrieval.
Aligned NIST CSF 2.0 outcomes (12)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-07mostlyaligns with — Defining record types, retention periods, and storage media requirements establishes and maintains inventories of data and corresponding metadata for designated data types.
- ID.AM-08mostlyaligns with — Managing records through defined retention schedules, storage media selection, and eventual destruction implements lifecycle management for data assets.
- PR.DS-01mostlyaligns with — The ISO control's focus on preserving record authenticity, integrity, and usability over time directly supports protecting the confidentiality, integrity, and availability of data-at-rest.
- GV.OC-03partialaligns with — Incorporating national, regional, and societal requirements into retention schedules and handling procedures addresses legal, regulatory, and contractual obligations.
- PR.DS-11partialaligns with — Retaining records and ensuring their retrievability and format readability throughout the retention period aligns with the creation, protection, and maintenance of backups.
- PR.PS-01partialaligns with — Issuing guidelines for storage, handling, chain of custody, and disposal of records establishes configuration management practices for record-keeping systems.
Related OWASP ASVS 5.0 requirements (10)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V14.2.7mostlyaligns with — The ISO control's retention schedule and defined destruction after the retention period directly implement the ASVS requirement that sensitive information be subject to data retention classification with automatic deletion of outdated data.
- V13.3.4partialaligns with — The ISO control's mandate to retain cryptographic keys for the full retention period of encrypted records aligns with the ASVS requirement that secrets be configured to expire and be rotated based on documented policy.
- V14.2.4partialaligns with — By requiring protection of authenticity, integrity and usability of records according to their security classification, the ISO control partially satisfies the ASVS requirement that controls around encryption, integrity verification, retention and access be defined for sensitive data.
- V16.2.3partialaligns with — The ISO control's requirement that records be stored only in approved systems and media that permit retrieval within the retention period aligns with the ASVS requirement that logs be stored or broadcast only to documented services.
Related weaknesses / CWE (5)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200partialprevents — Retention schedules and controlled disposal procedures reduce the window during which sensitive records remain accessible, lowering the chance of unauthorized exposure after their business need ends.
- CWE-532partialmitigates — By defining what records must be kept, where, and for how long, the control discourages the inadvertent inclusion of sensitive information in logs or other externally accessible files that fall outside the formal record system.
- CWE-1301nonenone — Protection of records implies proper disposal but does not prescribe hardware-level removal methods.
- CWE-284nonemitigates — Guidelines on storage, chain-of-custody and access aligned to classification limit who can read or alter records, thereby constraining improper access control weaknesses.
- CWE-312nonenone — Requiring retention of cryptographic keys alongside encrypted records prevents loss of confidentiality that would otherwise occur if encrypted data became unreadable or keys were discarded prematurely.
Prevented OWASP Web Top 10 (2025) risks (3)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A08mostlyprevents — Guidelines that prevent manipulation of records and enforce retention schedules reduce the likelihood that stored data or software artifacts can be altered without detection, limiting integrity failures.
- A04partialmitigates — Retaining cryptographic keys and ensuring long-term readability of encrypted records directly reduces the chance that cryptographic material becomes unavailable or unusable, thereby lowering the impact of cryptographic failures on stored data.
- A09partialmitigates — Requiring identification of records, retention periods, and chain-of-custody procedures creates an auditable trail that supports reliable logging and alerting for access or modification events.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.