SI-12 Information management and retention
Requires information held in the system and information produced as output to be managed and retained in line with applicable laws, directives, regulations, policies, standards, guidelines and operational needs, covering
system holds itEvidence a system already holds
- Configuration or process evidence implementing retention and disposal · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Disposal records for information that reached the end of its retention period · Data governance / DLP tooling
- Coverage evidence for system outputs such as reports, extracts and archives · Document repository
governing documentDocuments that govern the control
- Retention schedule mapping information types to retention periods and their legal basis · Policy repository / GRC workspace
First move
Common gaps auditors find
- Retention defined for records systems while exports, reports and backups are unmanaged
- Data kept indefinitely because deletion is harder than storage
- Legal basis for the retention period never recorded
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSI-11 Error Handling. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and Reveal error messages only to [organization-defined] · SI-13 Predictable Failure Prevention. Determine mean time to failure (MTTF) for the following system components in specific environments of operation: [organization-defined] ; and Provide substitute system components and a means to exchange active and standby