SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.33Protection of records

Protect important records against loss, destruction, falsification and unauthorized access, in line with legal, regulatory and business needs for how long to keep them.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0018Regulatory compliance · TechnicalrelatedUsing system configuration to satisfy regulatory requirements automatically applies broadly across compliance, and specifically supports the retention and disposal rules this control requires be enforced technically.RCF-0109Data retention & disposal · PolicysupportsAn approved retention schedule stating how long each data category is kept and how it is securely destroyed supports this control by setting the timeline records must be protected before disposal, though it does not address falsification or access controls.RCF-0110Data retention & disposal · ProcesssupportsRunning disposals on schedule across paper, devices and digital records, with a log of what was destroyed, supports this control by covering the disposal end of the record lifecycle it protects.RCF-0373Control evidence management · PolicysupportsStating in writing which controls require retained evidence and how long it is kept extends this control's record-protection principle to the audit evidence itself.RCF-0374Control evidence management · ProcesssupportsCollecting and filing control evidence consistently as work happens is a form of record protection that keeps proof available and unaltered for the retention period required.RCF-0375Control evidence management · TechnicalenablesAutomated evidence capture feeding one organised library reduces the risk that control evidence records are lost or scattered across individual machines.RCF-0383Audit readiness · ProcessrelatedPeriodic internal spot-checks that confirm evidence is current touch record protection indirectly, by catching missing or stale records before an external audit does.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Data retention and disposal procedure
The rules on how long data is kept and how it is securely destroyed when no longer needed.
Backup configuration and restore-test record
How backups are made (what is backed up, how often, where they are stored) and the proof that a restore has been tested successfully.
From the Sekit evidence catalog

In practice

Protecting records is mostly about knowing when to stop keeping them. A retention schedule that states how long each category of data is kept and when it must be destroyed protects the company two ways: it limits what an attacker could steal, and it avoids keeping data past the point the law allows. The common failure is a backup system that quietly retains everything forever because nobody set an expiry, so a customer's deletion request gets honored in the production database but their data still exists in an old backup nobody expired. Disposal records, showing what was destroyed, when and how, matter as much as the schedule itself when an auditor asks for proof.

Common gaps

Data is kept indefinitely in backups and archives with no defined destruction date, well past the retention period stated in policy.
Physical records with personal data are shredded inconsistently, with some offices using a locked bin and others the regular trash.
The retention schedule exists but has never been checked against actual system configuration, so automatic deletion is not happening.

Questions your auditor will ask

How long is each category of data kept, and what happens after that?
A retention schedule states the retention period and legal minimum for each data category, along with the secure disposal method used afterward.
Is there proof that disposal happened?
Disposal records log what was destroyed, when and how, for every scheduled destruction of paper, devices and digital records.
How do you know evidence of controls hasn't been altered or lost?
The evidence library restricts write access to a small admin group, and automated capture pulls files straight from source systems, so entries cannot be edited or deleted after logging without leaving a trace.

Where regulation demands it

NIS2 12.5 requires the return or secure deletion of assets, which applies directly to records that have reached the end of their retention period.
ENS mp.si.2 covers cryptography, relevant when disposal relies on cryptographic erasure of encrypted records rather than physical destruction.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.33?”
Also via MCP, free with account