SI-12: Information Management and Retention

SI-12 requires your organization to manage and retain all information within and produced by your systems according to applicable laws, r...

Quick-reference card

FieldDetail
Control IDSI-12
Control NameInformation Management and Retention
FrameworkNIST SP 800-53 Revision 5
Control FamilySystem and Information Integrity
BaselinesLOW MODERATE HIGH PRIVACY
RelevanceOrganization (First Party and Third Party)
Risk SeverityMedium

What this control requires

SI-12 requires your organization to manage and retain all information within and produced by your systems according to applicable laws, regulations, and operational requirements. That means every record your systems generate, from audit logs to access control lists, must follow a defined lifecycle with documented retention schedules and disposal procedures.

In practice, this control extends well beyond keeping files around. It covers the full information lifecycle, from creation through active use to archival and eventual disposal. Your system and information integrity policies must define how long each category of information is retained, who is responsible for managing it, and how disposal is carried out when records reach end of life.

The scope is broad because NIST intentionally connects SI-12 to dozens of other controls that produce records requiring retention. Plans, reports, assessment results, configuration baselines, incident response logs, and personnel security records all fall under its umbrella. Failing to retain these records doesn’t just create compliance gaps; it undermines your ability to demonstrate due diligence during an audit or investigation.

Why it matters

Most organizations treat records retention as an administrative afterthought until an auditor asks for evidence they can’t produce. Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. When retention policies are absent or inconsistently applied, your organization loses the ability to prove that other controls were implemented and operating effectively.

The downstream consequences compound quickly. Without retained audit records, you can’t demonstrate continuous monitoring was performed. Without archived access control lists, you can’t verify that least-privilege principles were enforced at a specific point in time. Regulators and assessors treat missing evidence as a control failure, regardless of whether the underlying control was operating.

Specifically, federal agencies must also align their retention schedules with National Archives and Records Administration (NARA) guidance, adding another layer of regulatory obligation. Organizations with a records management office should coordinate directly with that function to avoid conflicting retention periods or premature disposal.

What attackers exploit

  • Premature record disposal that eliminates forensic evidence needed to detect and investigate intrusions after the fact
  • Inconsistent retention policies across systems, allowing adversaries to target environments where their activity won’t be logged long enough for detection
  • Unmanaged information output from systems that creates shadow data stores outside the retention framework, giving attackers persistent access to sensitive records
  • Missing personally identifiable information (PII) inventories that leave organizations unable to determine the scope of a data exposure event

How to implement

The most common failure mode is treating retention as a single policy document rather than an operational program. Organizations write the policy, file it away, and never build the processes to enforce it across systems and information types.

For your organization

Start by inventorying the categories of information your systems produce. Map each category to applicable retention requirements from federal law, agency directives, and NARA schedules. Your records retention and disposition policy should define retention periods for each category, assign ownership, and specify approved disposal methods.

In practice, your retention schedule should center on the records that NIST explicitly calls out as requiring management. Assessment reports from CA-2, plan of action and milestones from CA-5, authorization packages from CA-6, continuous monitoring outputs from CA-7, and configuration baselines from CM-2 all require defined retention periods. Don’t treat this list as exhaustive; use it as a starting point and extend coverage to every control that produces auditable output.

Where this breaks down for most teams is the gap between policy and enforcement. Implement technical controls to enforce retention automatically where possible. Configure audit log retention in your security information and event management (SIEM) platform to match policy requirements. Set up automated archival workflows for records that must be preserved beyond their active use period. Ensure that disposal processes include verification steps, such as cryptographic erasure certificates or witnessed physical destruction, to create defensible evidence of proper handling.

The result is that retention becomes a sustained program rather than a one-time policy exercise. Coordinate with your records management office if one exists. Assign a records coordinator within the security team to serve as a liaison. Review retention schedules at least annually and update them when new regulations, directives, or operational requirements change the retention landscape. Document every review, even when no changes are made, because auditors look for evidence of periodic reassessment.

Your media protection procedures should align with your retention and disposal requirements. When media reaches end of life or records reach their retention expiry, follow documented sanitization or destruction procedures that produce verifiable evidence of completion.

For your vendors

When evaluating third-party compliance with SI-12, request their records retention and disposition policy and verify it addresses the specific information categories relevant to your engagement. A generic “we retain records for seven years” statement doesn’t satisfy the control; vendors must demonstrate that retention periods are mapped to specific regulatory and operational requirements.

Specifically, ask vendors to provide evidence of their retention schedule, including which laws, directives, or standards drive each retention period. Request documentation showing how they handle information output from systems that process your data, particularly PII. Verify that their privacy impact assessments address retention and disposal of personally identifiable information.

But the real test comes during assessments, where you should look for red flags that indicate a paper-only approach. If a vendor has a retention policy but can’t produce audit logs from six months ago, the policy isn’t being enforced. Request specific evidence artifacts, such as disposal verification records, archival access logs, or SIEM retention configurations, to validate that technical implementation matches written policy.

Your vendor risk management program should include SI-12 compliance verification as part of ongoing monitoring, not just initial assessment. Retention practices can degrade over time as systems change, staff turns over, or storage costs pressure teams to delete records prematurely. Include retention compliance in your periodic reassessment questionnaire and flag any vendors who can’t demonstrate consistent adherence.

Take federal records handling as a specific case. Evaluate whether vendors coordinate with regulatory bodies like NARA when handling federal records on your behalf. For vendors processing government data, this coordination isn’t optional. Review their procedures for transferring records back to you at contract termination and verify that disposal of your data follows your retention requirements, not theirs.

Evidence examples

Evidence TypeExample Artifact
Retention policy and proceduresRecords retention and disposition policy defining retention periods by information category, applicable legal authorities, and approved disposal methods
System and information integrity documentationSystem and information integrity policy and procedures specifying how information within systems is managed, archived, and disposed of across the lifecycle
PII management recordsPersonally identifiable information inventory, privacy impact assessment, and privacy risk assessment documentation demonstrating retention controls for sensitive data
Media protection documentationMedia protection policy and procedures defining sanitization and destruction methods for media containing retained records
Audit and assessment evidenceAudit findings, control assessment reports, system security plan, and privacy plan documenting the effectiveness of retention controls
Legal and regulatory authority mappingDocumented mapping of applicable federal laws, executive orders, directives, regulations, and standards to specific retention periods and information categories

Cross-framework mapping

FrameworkControl(s)Coverage
NIST SP 800-171 Rev 303.14.08 Information Management and RetentionPartial
  • AC-16 — Security and Privacy Attributes: defines metadata tagging that supports categorization and retention decisions for information assets
  • AU-05 — Response to Audit Logging Process Failures: ensures audit records aren’t lost due to system failures, protecting the data SI-12 requires you to retain
  • AU-11 — Audit Record Retention: specifies retention periods for audit logs, a critical subset of the broader information retention requirements in SI-12
  • CA-02 — Control Assessments: produces assessment reports that must be retained as evidence of control effectiveness under SI-12
  • CA-03 — Information Exchange: documents interconnection agreements whose records fall under SI-12 retention requirements
  • CA-05 — Plan of Action and Milestones: generates remediation tracking records that auditors expect to find retained per SI-12
  • CA-06 — Authorization: produces authorization packages and decisions that must be preserved throughout the system lifecycle
  • CA-07 — Continuous Monitoring: creates ongoing monitoring outputs that serve as retained evidence of security posture over time
  • CA-09 — Internal System Connections: documents internal connection authorizations whose records must be managed under SI-12
  • CM-05 — Access Restrictions for Change: produces change control records that demonstrate configuration integrity when retained per SI-12

Frequently asked questions

What is NIST SP 800-53 SI-12

SI-12 requires organizations to manage and retain information within their systems and information output from their systems in accordance with applicable laws, regulations, and operational requirements. This control covers the full lifecycle of information, from creation and active use through archival and disposal. It connects directly to dozens of other NIST controls that produce auditable records, including assessment reports, configuration baselines, and incident response documentation.

What happens if SI-12 is not implemented

Without SI-12, your organization can’t produce the retained evidence that auditors and regulators require to verify other controls are operating effectively. Missing records retention and disposition procedures mean you won’t have a defensible position during a federal audit or certification assessment. Gaps in retained audit records and PII inventory documentation can lead to findings, corrective action requirements, or certification withdrawal. Organizations that monitor their external attack surface but neglect internal records retention still face significant audit exposure.

How do you audit SI-12

Auditors verify that information within systems and information output from systems are both managed and retained according to documented policies aligned with applicable legal and regulatory authorities. They’ll request your records retention and disposition policy, examine retention schedules for specific information categories, and test whether technical controls enforce the stated retention periods. Assessors also check that your personally identifiable information inventory and privacy impact assessments reflect current retention practices, and that media protection procedures include verifiable disposal evidence.

What records must be retained under NIST SP 800-53 SI-12

SI-12 covers policies, procedures, plans, reports, and data output from implemented controls, including but not limited to assessment reports, authorization packages, continuous monitoring outputs, configuration baselines, incident response logs, and personnel security records. The National Archives and Records Administration provides federal retention schedules that agencies must follow. Your organization should map every control that produces auditable output to a specific retention period documented in your records retention and disposition policy.

Experience superior visibility and a simpler approach to cyber risk management