ISO 27001 5.33 Protection of Records Requirement:
"Records shall be protected from loss, destruction, falsification, unauthorized access and unauthorized release."[1]
ISO 27001 5.33 Protection of Records Requirement Explanation:
The organization should issue guidelines on the storage handling and disposal of digital and non-digital records. The organization must also create a record retention schedule (e.g. 10 years) after which records may be securely disposed. Depending on legal and business requirements different types of records may have different retention periods.
References:
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you