Protect important records against loss, destruction, falsification and unauthorized access, in line with legal, regulatory and business needs for how long to keep them.
What an auditor, or Sekit's evidence engine, asks for.
Data retention and disposal procedure
The rules on how long data is kept and how it is securely destroyed when no longer needed.
Backup configuration and restore-test record
How backups are made (what is backed up, how often, where they are stored) and the proof that a restore has been tested successfully.
From the Sekit evidence catalog
In practice
Protecting records is mostly about knowing when to stop keeping them. A retention schedule that states how long each category of data is kept and when it must be destroyed protects the company two ways: it limits what an attacker could steal, and it avoids keeping data past the point the law allows. The common failure is a backup system that quietly retains everything forever because nobody set an expiry, so a customer's deletion request gets honored in the production database but their data still exists in an old backup nobody expired. Disposal records, showing what was destroyed, when and how, matter as much as the schedule itself when an auditor asks for proof.
Common gaps
Data is kept indefinitely in backups and archives with no defined destruction date, well past the retention period stated in policy.
Physical records with personal data are shredded inconsistently, with some offices using a locked bin and others the regular trash.
The retention schedule exists but has never been checked against actual system configuration, so automatic deletion is not happening.
Questions your auditor will ask
How long is each category of data kept, and what happens after that?
A retention schedule states the retention period and legal minimum for each data category, along with the secure disposal method used afterward.
Is there proof that disposal happened?
Disposal records log what was destroyed, when and how, for every scheduled destruction of paper, devices and digital records.
How do you know evidence of controls hasn't been altered or lost?
The evidence library restricts write access to a small admin group, and automated capture pulls files straight from source systems, so entries cannot be edited or deleted after logging without leaving a trace.
Where regulation demands it
NIS2 12.5 requires the return or secure deletion of assets, which applies directly to records that have reached the end of their retention period.
ENS mp.si.2 covers cryptography, relevant when disposal relies on cryptographic erasure of encrypted records rather than physical destruction.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.