Quick-reference card
| Field | Detail |
|---|---|
| Control ID | SI-21 |
| Control Name | Information Refresh |
| Framework | NIST SP 800-53, Revision 5 |
| Control Family | System and Information Integrity |
| Baselines | — |
| Relevance | First Party and Third Party (Organization and Vendor) |
| Risk Severity | Low |
What this control requires
SI-21 requires organizations to periodically refresh designated information at defined frequencies, or generate that information on demand and delete it when it’s no longer needed. The control targets a problem most teams underestimate: data that sits untouched in systems long past its useful life becomes a growing liability rather than an asset.
In practice, this control means identifying which categories of information your organization stores, deciding how often each category needs to be refreshed to remain accurate and relevant, and enforcing those refresh cycles through documented procedures. The goal isn’t just housekeeping. Stale data creates blind spots in security monitoring, skews risk assessments, and gives adversaries a larger window to locate, exfiltrate, or manipulate information that should have been purged or updated.
Within the broader NIST SP 800-53 framework, the “generate on demand and delete when no longer needed” clause addresses a complementary pattern. Rather than maintaining persistent copies of sensitive data, organizations can produce information only at the point of use, then remove it immediately afterward. This approach reduces the attack surface by minimizing how long exploitable data exists in the environment.
Why it matters
Organizations that retain information beyond its operational usefulness don’t just accumulate storage costs. They accumulate risk. Every additional day that outdated, redundant, or obsolete data remains in a system expands the window for unauthorized access, accidental disclosure, or regulatory noncompliance.
From an audit perspective, the absence of defined refresh procedures signals a broader gap in system and information integrity controls. Assessors look for documented evidence that organizations know what data they hold, how often it’s refreshed, and when it’s scheduled for deletion. Without that evidence, passing a NIST SP 800-53 assessment becomes significantly harder.
The compliance risk extends beyond audit findings. Regulations like GDPR, CCPA, and sector-specific frameworks increasingly require organizations to demonstrate data minimization practices. SI-21’s refresh and delete-on-demand requirements align directly with these obligations. Failing to implement them can trigger regulatory penalties and erode trust with customers and partners who expect disciplined data governance.
What attackers exploit
Threat actors specifically target environments where information lingers past its useful life. Common vectors include:
- Stale credential stores that retain outdated access tokens, API keys, or cached authentication data attackers can harvest for lateral movement
- Unrefreshed configuration data that preserves deprecated settings, default passwords, or outdated firewall rules attackers exploit to bypass current defenses
- Retained personally identifiable information (PII) that accumulates in logs, backups, and staging environments, creating high-value targets for data exfiltration
- Obsolete system inventories that mask rogue or decommissioned assets still connected to the network, providing unmonitored entry points
- Cached analytical datasets containing sensitive operational metrics that provide adversaries with reconnaissance intelligence about organizational processes
How to implement
The most common failure point with SI-21 isn’t a lack of intent. It’s the gap between policy and execution, where organizations define refresh requirements on paper but lack the automation or accountability structures to enforce them consistently.
For your organization
Start by building a comprehensive list of information categories your organization stores, maps, or processes. This list of information to be refreshed is the foundational artifact auditors will request, and it should specify each data type alongside its designated refresh frequency.
Define refresh frequencies based on the sensitivity and operational relevance of each category. High-sensitivity data like active threat intelligence feeds or access control lists may require daily or weekly refresh cycles. Lower-sensitivity reference data might warrant monthly or quarterly updates. Document these frequencies in your system and information integrity policy and link them to specific system components.
Develop information refresh procedures that detail who is responsible for each refresh action, what tools or scripts execute the refresh, and how completion is verified. Automated approaches are strongly preferred. Manual refresh processes introduce human error and tend to degrade over time as team priorities shift.
Implement technical controls that enforce deletion timelines. Configure data retention policies in databases, file systems, and cloud storage to automatically purge information that exceeds its defined lifespan. For on-demand generation scenarios, build workflows that create temporary data objects with automatic expiration. Organizations using attack surface management tools can identify where stale data persists across exposed assets, ensuring information doesn’t linger after its immediate purpose is fulfilled.
Produce and maintain evidence that refresh cycles are executing as designed. System logs showing refresh timestamps, automated deletion confirmations, and periodic compliance reports all serve as proof during assessments. Common tooling categories include data lifecycle management platforms, configuration management databases, and security information and event management (SIEM) systems that can track data-age metrics.
Avoid a common mistake: treating SI-21 as a one-time cleanup project. Information refresh is a continuous operational discipline. Without recurring reviews of your data inventory and refresh schedules, new data categories accumulate without governance, and the control degrades.
For your vendors
When assessing third-party compliance with SI-21, focus on whether the vendor has operationalized information refresh rather than simply documented it.
Ask targeted questionnaire questions during vendor assessments. Request that vendors describe their process for identifying which information categories require periodic refresh. Ask how refresh frequencies are determined and whether those frequencies are documented in a formal policy. Inquire about the tools or automation vendors use to enforce refresh cycles and deletion timelines.
Request specific evidence artifacts. A vendor risk assessment should include the vendor’s list of information subject to refresh, their documented refresh procedures, and logs or reports demonstrating that refresh actions have been executed on schedule. Configuration screenshots showing automated deletion policies in cloud environments or databases add credibility.
Watch for red flags during vendor evaluation. Vendors who can’t produce a defined list of information subject to refresh likely haven’t implemented the control. Inconsistent or missing refresh logs suggest the process exists only on paper. Vendors relying entirely on manual processes for data refresh and deletion present higher risk, since manual approaches are prone to gaps and harder to verify.
Verify vendor claims through independent evidence. Don’t accept self-attestation alone. Request system-generated logs rather than manually compiled summaries, and compare stated refresh frequencies against actual log timestamps. Organizations using a vendor risk management platform can streamline this evidence collection and track vendor compliance posture over time.
Evidence examples
| Evidence Type | Example Artifact |
|---|---|
| Policy documentation | System and information integrity policy defining information refresh requirements, frequencies, and accountable roles |
| Refresh procedures | Information refresh procedures specifying step-by-step actions, automation scripts, and verification checkpoints for each data category |
| Data inventory | List of information to be refreshed, including data classification, storage location, designated refresh frequency, and deletion criteria |
| System documentation | System design documentation showing how refresh and on-demand generation mechanisms are architected within the environment |
| Configuration evidence | System configuration settings demonstrating automated retention policies, scheduled purge jobs, and expiration rules |
| Privacy documentation | PII processing policy and privacy plan addressing refresh and deletion requirements for personally identifiable information |
| Assessment records | Audit logs, refresh completion reports, and compliance review records confirming refresh cycles executed on schedule |
Cross-framework mapping
| Framework | Control(s) | Coverage |
|---|---|---|
| ISO 27001:2022 | 8.10 Information deletion | Partial |
Related controls
- SI-14, Non-persistence: SI-14 addresses systems designed to operate in a non-persistent state, where components are refreshed or regenerated at defined intervals, complementing SI-21’s focus on refreshing the information itself rather than the underlying system or platform.
Frequently asked questions
What is NIST SP 800-53 SI-21?
SI-21 requires organizations to refresh designated information at defined frequencies or generate it on demand and delete it once it’s no longer needed. The control reduces the window of exposure by ensuring that data doesn’t persist in systems beyond its operational usefulness. It applies to any information category an organization determines carries risk when retained, from cached credentials to outdated configuration data.
What happens if SI-21 is not implemented?
Without SI-21 controls in place, stale and obsolete information accumulates across systems, expanding the attack surface and creating targets for adversaries seeking high-value data. Audit assessors will flag the absence of a documented list of information to be refreshed and missing refresh procedures as control gaps. Organizations also risk noncompliance with data minimization requirements under frameworks like GDPR and CCPA, which can result in regulatory penalties.
How do you audit SI-21?
Auditing SI-21 starts with verifying that the organization maintains a current list of information subject to refresh, with defined refresh frequencies for each category. Assessors then examine information refresh procedures for completeness and review system logs or automated reports confirming that refresh actions execute on schedule. The assessment objective confirms that designated information is refreshed at the stated frequencies or is generated on demand and deleted when no longer needed.
What is the difference between information refresh and data retention?
Information refresh, as defined by SI-21, focuses on replacing or regenerating data at set intervals so that the information in active use stays current and accurate. Data retention policies, by contrast, govern how long information is stored before it’s archived or permanently deleted. The two disciplines complement each other: refresh frequencies determine how often active data is updated, while retention schedules determine when data reaches end-of-life and must be purged from all systems.