A.5.33 Organizational
Protection of records
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (18)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AU-11mostlyaligns with — Both controls mandate retention schedules and protection measures that ensure audit records remain authentic, unaltered, and retrievable for the required duration.
- SI-12mostlyaligns with — Both controls require organizations to define retention periods, storage methods, and destruction procedures that preserve the integrity and accessibility of records throughout their lifecycle.
- SI-12mostlycovers — A.5.33's focus on protecting records to meet legal/societal expectations accounts for the bulk of SI-12's retention-and-management obligations under laws and policies, but leaves a residual on pure availability/operational retention aspects not centered on protection.
- AU-11partialcovers — A.5.33's broad requirement to protect records (including availability) to meet all legal/regulatory/contractual obligations accounts for only a slice of AU-11's specific audit-record retention period and investigative-support purpose; the bulk of AU-11's operational retention mechanics and audit-specific focus sit outside A.5.33.
- CM-2partialaligns with — Both controls require documented configurations for storage systems and media handling to ensure consistent, reliable access to retained records over time.
- MP-6partialaligns with — Both controls address the secure disposal of media or records once their retention period expires to prevent unauthorized access or manipulation.
- SC-28partialaligns with — Both controls require protection of stored information against loss of integrity or accessibility, including handling of encryption keys needed for long-term retrieval.
- CM-2covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- MP-6covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- SC-28covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (22)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- ID.AM-07mostlyaligns with — Defining record types, retention periods, and storage media requirements establishes and maintains inventories of data and corresponding metadata for designated data types.
- ID.AM-08mostlyaligns with — Managing records through defined retention schedules, storage media selection, and eventual destruction implements lifecycle management for data assets.
- PR.DS-01mostlyaligns with — The ISO control's focus on preserving record authenticity, integrity, and usability over time directly supports protecting the confidentiality, integrity, and availability of data-at-rest.
- GV.OC-03partialaligns with — Incorporating national, regional, and societal requirements into retention schedules and handling procedures addresses legal, regulatory, and contractual obligations.
- PR.DS-11partialaligns with — Retaining records and ensuring their retrievability and format readability throughout the retention period aligns with the creation, protection, and maintenance of backups.
- PR.PS-01partialaligns with — Issuing guidelines for storage, handling, chain of custody, and disposal of records establishes configuration management practices for record-keeping systems.
- GV.OC-03implements — A.5.33 operationalizes the protection and availability of records to meet exactly the legal/regulatory/contractual obligations that GV.OC-03 requires an organization to understand and manage; the link is by shared subject domain rather than explicit citation of one by the other.
- ID.AM-07implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.AM-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.DS-01implements — A.5.33 operationalizes protection and availability of records (a form of data-at-rest) to meet legal and societal requirements, which directly serves the PR.DS-01 outcome within its data-protection domain without the outcome naming this specific control
- PR.DS-11implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (10)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V14.2.7mostlyaligns with — The ISO control's retention schedule and defined destruction after the retention period directly implement the ASVS requirement that sensitive information be subject to data retention classification with automatic deletion of outdated data.
- V13.3.4partialaligns with — The ISO control's mandate to retain cryptographic keys for the full retention period of encrypted records aligns with the ASVS requirement that secrets be configured to expire and be rotated based on documented policy.
- V14.2.4partialaligns with — By requiring protection of authenticity, integrity and usability of records according to their security classification, the ISO control partially satisfies the ASVS requirement that controls around encryption, integrity verification, retention and access be defined for sensitive data.
- V16.2.3partialaligns with — The ISO control's requirement that records be stored only in approved systems and media that permit retrieval within the retention period aligns with the ASVS requirement that logs be stored or broadcast only to documented services.
Related weaknesses / CWE (3)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-284nonemitigates — Guidelines on storage, chain-of-custody and access aligned to classification limit who can read or alter records, thereby constraining improper access control weaknesses.
- CWE-200prevents — Retention schedules and controlled disposal procedures reduce the window during which sensitive records remain accessible, lowering the chance of unauthorized exposure after their business need ends.
- CWE-532mitigates — By defining what records must be kept, where, and for how long, the control discourages the inadvertent inclusion of sensitive information in logs or other externally accessible files that fall outside the formal record system.
Mitigated MITRE ATT&CK techniques (154)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1485recovers — A.5.33 mandates retention schedules, media choices, cryptographic key retention, and procedures to ensure records remain retrievable in acceptable form throughout their required period, directly enabling recovery of protected records after adversary destruction of data/files.
- T1486recovers — A.5.33 mandates retention schedules, protected storage, media/format longevity measures and explicit retention of decryption keys/cryptographic material so that records remain retrievable throughout (and can be restored from) their required period, directly enabling recovery from ransomware-style encryption of those records; mostly because the clause is scoped to organization-defined records rather than every possible file an adversary may encrypt.
- T1490recovers — A.5.33 mandates retention schedules, protected storage/handling with chain-of-custody, media/format longevity measures, and cryptographic-key retention to keep records retrievable throughout their required period, directly enabling recovery of the very backup/snapshot/record artifacts that T1490 targets for deletion.
- T1552.004prevents — A.5.33 mandates guidelines, retention schedules, classification-driven storage/handling rules, media choices, and procedures (including retention of associated keys) that directly constrain insecure placement and long-term exposure of private keys used in records, but leaves many non-record keys, export mechanisms, and post-compromise search vectors untouched.
- T1561recovers — A.5.33 mandates retention schedules, protected storage, and procedures (including media/format longevity and retained keys) that enable retrieval of records after destructive events such as disk wiping, directly enacting recovery of availability for retained records.
- T1561.001recovers — A.5.33 explicitly requires retention schedules, protected storage, media/format readability procedures throughout the retention period, and retention of keys/programs for encrypted records so that records can be retrieved after destructive events such as disk-content wipe.
- T1561.002recovers — A.5.33 requires retention schedules, protected storage, and procedures (including for electronic media and cryptographic material) that enable retrieval of records throughout their mandated period, directly supporting recovery of availability for retained records after a disk-structure wipe.
- T1565detects — A.5.33's guidelines on storage/handling, chain-of-custody, retention, and media procedures can surface unauthorized manipulation of records when those controls are monitored or audited, but the clause itself is about establishing protective processes rather than mandating detection mechanisms.
- T1565prevents — A.5.33 guidelines on storage/handling/chain-of-custody explicitly include prevention of manipulation of records and require retention schedules plus media procedures that protect integrity and authenticity over time, directly blocking T1565's insert/delete/manipulate actions on those records; partial because the control is scoped to organizational records (not all data) and its effect is governance/procedural rather than a technical barrier that stops every possible manipulation technique on every platform.
- T1565.001prevents — A.5.33 guidelines on storage/handling, chain-of-custody, manipulation prevention, retention, and media procedures directly constrain the ability to insert/delete/manipulate data at rest, but only for organizationally-defined records under a classification scheme and do not address all stored data types or adversary techniques on non-record files.
- T1565.002prevents — A.5.33 guidelines on storage/handling, chain-of-custody, retention, and media procedures (including anti-manipulation and cryptographic-key retention) constrain opportunities for in-transit alteration of records before they reach protected storage, but address only the records subset of transmitted data and do not stop the technique on non-record flows or during active interception.
Prevented OWASP Web Top 10 (2025) risks (4)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A04mitigates — A.5.33 requires retaining cryptographic keys and programs for encrypted records/archives throughout the retention period (explicitly referencing 8.24), which bounds the realized impact of weak/misused cryptography on those records by keeping decryption feasible; this is mitigation of consequence for a realized weakness rather than prevention or removal, but only a slice of A04 (long-term encrypted records) is reached while transit, absent crypto, and most key-management failures remain untouched.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.