ISO27001:2022 – A5.33 – Protection of records

Introduction to ISO 27001 – A5.33

Among all the ISO27001 controls, ISO 27001 – A5.33 is the only one that explicitly mentions the word “records.” Until now, most of the focus has been on data and information—but this control brings our attention to the complete picture: records.

What does the standard require?

“Records shall be protected from loss, destruction, falsification, unauthorised access and unauthorised release.”

(ISO 27001 – A5.33 – Protection of Records)

Why is this required?

If data is the building block and information is the partially completed puzzle, then records represent the complete jigsaw. When all your data comes together—names, addresses, actions, behaviours—it forms a powerful and often sensitive picture.

For example, a leaked email address is concerning. But a leaked complete medical record is devastating. That’s the difference between information and records—and why this control is critical.

We worked with a law firm that stored case files in reception before courier pickup. These boxes could sit for hours in an unsecured public area. That’s a clear risk—and one that was easily fixed with better planning.

What the auditor is looking for

This control is not implemented in isolation. The auditor will look for the combined effect of several other controls to confirm that your records are being protected:

They’ll also expect to see technical controls, audits, and perhaps physical security measures around how records are accessed, stored, and transferred.

What do you need to do?

This is a relatively easy control to satisfy if your other Annex A controls are already in place and working well. Here’s how you can approach it:

  1. Review your data retention and classification policies (see A5.1 and A5.12).
  2. Assess how you store and transfer records—both physical and digital.
  3. Check whether access control measures are being applied to records just as thoroughly as they are to data.
  4. Update your internal processes if you identify unsecured locations or gaps (like the law firm’s reception example).

If you treat data securely, protecting records should be a logical extension of that effort.

Q & A

Do I need a separate policy for records?

No, not specifically. This control doesn’t require a new standalone policy, but the protection of records should be evident in your existing policies and practices.

Are there specific records I need to worry more about?

Yes. You likely identified sensitive records in A5.12 – Classification of Information. These will often include:

  • Medical or health records
  • Financial data
  • Client case files
  • HR records

These should be treated with heightened care due to their sensitivity and potential impact if compromised.

Difficulty Rating

1 out of 5 – This control is straightforward and non-technical. If you’ve properly implemented your other ISO27001 controls, then this is simply about tying it all together and making sure your records are as protected as your data and information.

More Questions?

Remember: ISO27001 is an interconnected standard. Controls like this one rely on strong implementation elsewhere. If you’re still unsure, or if you want help preparing for audit, feel free to reach out.

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” – available now on Amazon.

ISO 27001 – A5.33