{"data":{"id":"SI-12","name":"Information Management and Retention","family":"SI","family_name":"System and Information Integrity","withdrawn":false,"description":"Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.","supplemental_guidance":"Information management and retention requirements cover the full life cycle of information, in some cases extending beyond system disposal. Information to be retained may also include policies, procedures, plans, reports, data output from control implementation, and other types of administrative information. The National Archives and Records Administration (NARA) provides federal policy and guidance on records retention and schedules. If organizations have a records management office, consider coordinating with records management personnel. Records produced from the output of implemented controls that may require management and retention include, but are not limited to: All XX-1, AC-06(09), AT-04, AU-12, CA-02, CA-03, CA-05, CA-06, CA-07, CA-08, CA-09, CM-02, CM-03, CM-04, CM-06, CM-08, CM-09, CM-12, CM-13, CP-02, IR-06, IR-08, MA-02, MA-04, PE-02, PE-08, PE-16, PE-17, PL-02, PL-04, PL-07, PL-08, PM-05, PM-08, PM-09, PM-18, PM-21, PM-27, PM-28, PM-30, PM-31, PS-02, PS-06, PS-07, PT-02, PT-03, PT-07, RA-02, RA-03, RA-05, RA-08, SA-04, SA-05, SA-08, SA-10, SI-04, SR-02, SR-04, SR-08.","enhancements":[{"id":"SI-12(01)","name":"Limit Personally Identifiable Information Elements","statement":"Limit personally identifiable information being processed in the information life cycle to the following elements of personally identifiable information: [Assignment: organization-defined elements of personally identifiable information].","baselines":["privacy"]},{"id":"SI-12(02)","name":"Minimize Personally Identifiable Information in Testing, Training, and Research","statement":"Use the following techniques to minimize the use of personally identifiable information for research, testing, or training: [Assignment: organization-defined techniques].","baselines":["privacy"]},{"id":"SI-12(03)","name":"Information Disposal","statement":"Use the following techniques to dispose of, destroy, or erase information following the retention period: [Assignment: organization-defined techniques].","baselines":["privacy"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SI-12","name":"Information Management and Retention","description":"Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.","discussion":"Information management and retention requirements cover the full life cycle of information, in some cases extending beyond system disposal. Information to be retained may also include policies, procedures, plans, reports, data output from control implementation, and other types of administrative information. The National Archives and Records Administration (NARA) provides federal policy and guidance on records retention and schedules. If organizations have a records management office, consider coordinating with records management personnel. Records produced from the output of implemented controls that may require management and retention include, but are not limited to: All XX-1, AC-06(09), AT-04, AU-12, CA-02, CA-03, CA-05, CA-06, CA-07, CA-08, CA-09, CM-02, CM-03, CM-04, CM-06, CM-08, CM-09, CM-12, CM-13, CP-02, IR-06, IR-08, MA-02, MA-04, PE-02, PE-08, PE-16, PE-17, PL-02, PL-04, PL-07, PL-08, PM-05, PM-08, PM-09, PM-18, PM-21, PM-27, PM-28, PM-30, PM-31, PS-02, PS-06, PS-07, PT-02, PT-03, PT-07, RA-02, RA-03, RA-05, RA-08, SA-04, SA-05, SA-08, SA-10, SI-04, SR-02, SR-04, SR-08.","related_controls":["AC-16","AU-05","AU-11","CA-02","CA-03","CA-05","CA-06","CA-07","CA-09","CM-05","CM-09","CP-02","IR-08","MP-02","MP-03","MP-04","MP-06","PL-02","PL-04","PM-04","PM-08","PM-09","PS-02","PS-06","PT-02","PT-03","RA-02","RA-03","SA-05","SA-08","SR-02"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":true,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Information Handling and Retention' Control text changes 'information handling' to 'information management' and changes the wording of the list of 'in accordance with' specifics Discussion adds recommendation to coordinate with records management personnel and references numerous other controls Incorporates data retention elements of withdrawn App J control DM-02"}},"compliance_mappings":{"iso_27001_2022":["A.5.33","A.8.10"],"iso_27002_2022":["5.33","8.10"],"cobit_2019":["APO14"],"pci_dss_v4":["3.2","3.3"],"nist_csf_2":["ID.AM-07","ID.AM-08"],"cis_controls_v8":["CIS 3","CIS 3.1","CIS 3.4","CIS 3.5"],"soc2_tsc":["C1.2","CC6.5","PI1.5"],"finos_ccc":[],"iso_42001_2023":["A.8.5"],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["CON.6"],"anssi":["Hygiene.8","Hygiene.19","SecNumCloud.9.2"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.D(78)","IV.D(82)","IV.E(83)"],"gdpr":["Art.5(1)(e)","Art.5(1)(f)","Art.17(1)","Art.32(1)(a)"],"dora":["Art.8(1)","Art.12(3)"],"bio2":["5.33","8.10"],"rbi_csf":["Annex1.15"],"fisc":["FISC.O9","FISC.T5"],"lgpd_bcb":["BCB.Art.9","BCB.Art.20","LGPD.Art.15-16"],"hkma_tme1":["TME1.6.5","TME1.7.2"],"mlps_2":["8.1.4.11"],"dnb_good_practice":["DNB.12.1","DNB.12.2","DNB.12.3"],"cra":["CRA.I.2g","CRA.I.2m"],"swift_cscf":[],"cbb_tm":["TM-9"],"cbuae":["CR-5"],"nca_ecc":["2-7"],"cbe_csf":["CTO-2"],"cbn_csf":["Part3.4","Part7.1"],"popia":["s14"],"sa_js2":["JS2-8.2"],"bcbs_239":["Principle 2","Principle 4"],"bot_cyber":["Ch2.3","Ch9.2"],"ecb_croe":["CROE.2.3.3"],"ffiec_is":["II.C.13","II.C.13(c)"],"hipaa_sr":["§164.316(b)(2)(i)"],"iosco_cyber":["PROT-3"],"nydfs_500":["500.13","500.18"],"sebi_cscrf":["DATALOC","PR.DS"],"cmmc_2":["SI"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":["CBEST.9"],"tiber_eu":["TIBER.CONF"],"pci_hsm":[],"common_criteria":["CC Part 2 — FDP"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.G.4"],"fda_21_cfr_11":["§11.10(c)","§11.10(k)"],"fda_cyber":[],"hitrust_csf":["06.b","13.c"],"iso_27799":[],"lloyds_ms":["BP2.2","MS1.1","MS2.1","MS5.1","MS6.1","MS7.1","MS8.7","MS13.2"],"naic_ds":["4-asset","8"],"nhs_dspt":["NDG-5.4"],"pra_ss1_23":["P3.2","P5.5"],"solvency_ii":["Art.49(3)","DR.266-DataSec","EIOPA-Cloud-GL9","Pillar3-Reporting"],"owasp_masvs_v2":[],"csa_ccm_v4":["DSP-02","DSP-16"],"csa_aicm":["DSP-02","DSP-16","DSP-21","DSP-24"],"ccss_v9":["2.02.1"],"mica":["Art.82(1)"],"basel_sco60":["SCO60.70","SCO60.71"],"bssc":[],"sec_custody_digital":[],"dpdpa":["Act.6(1)","Act.8(7)","Act.12(3)","Rules.6(1)(e)","Rules.8(1)","Rules.8(3)","Rules.Sch1.B.3-4","Rules.Sch2"]},"attack_techniques":[{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Proper information handling and retention controls ensure that credential dumps and authentication databases are stored with appropriate protections and retention limits, reducing the volume of credential material available for adversary extraction."},{"id":"T1040","name":"Network Sniffing","tactics":["credential-access","discovery"],"mapping_type":"mitigates","mapping_rationale":"Information output handling controls that enforce encryption of sensitive data in transit and at rest reduce the value of network sniffing, as intercepted traffic contains properly protected information rather than cleartext credentials."},{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Retention policies that mandate secure, tamper-evident storage of audit logs and system outputs prevent adversaries from successfully removing indicators, as log data is preserved in accordance with regulatory requirements in protected repositories."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information handling controls governing email retention—including access restrictions, encryption requirements, and retention schedules—limit the volume of exploitable email data available for adversary collection from mailboxes and mail servers."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Output handling and retention controls restrict where sensitive information is stored and for how long, reducing the data footprint available for automated collection tools to harvest from information repositories and file shares."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information retention policies that enforce lifecycle management on cloud-stored data—including timely deletion of unnecessary data and access controls on retained information—reduce the volume of sensitive data exposed to adversary collection from cloud storage."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Proper handling of security-relevant system outputs—including privilege escalation logs and authorization records—ensures these audit trails are retained securely, enabling detection of elevation control abuse through forensic analysis of preserved records."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information handling controls that mandate secure storage and timely rotation of credentials, keys, and sensitive configuration data directly reduce the incidence of unsecured credentials persisting in files, registries, or other accessible locations."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Output handling controls that enforce encryption and integrity protection on sensitive data transmissions reduce the value of adversary-in-the-middle interception, as properly handled information remains protected regardless of network-level compromise."},{"id":"T1558","name":"Steal or Forge Kerberos Tickets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Retention and handling controls for Kerberos ticket caches, keytab files, and authentication tokens ensure these credential materials are stored with appropriate protections and purged on schedule, limiting adversary opportunities to steal or forge tickets."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Information output handling controls that enforce integrity verification, checksums, and audit trails on critical data outputs enable detection of data manipulation and provide authoritative records for restoring tampered information to its authentic state."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Handling and retention controls for network device configuration outputs ensure that exported configurations containing credentials and ACLs are stored securely and purged after operational need, reducing exposure to adversary collection."},{"id":"T1003.003","name":"NTDS","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Retention controls governing NTDS.dit backups and domain controller exports ensure these high-value credential stores are encrypted, access-restricted, and purged when no longer needed, limiting adversary access to offline copies of the Active Directory database."},{"id":"T1020.001","name":"Traffic Duplication","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Information output handling controls detect and prevent unauthorized traffic duplication by enforcing policies on how network data is captured, stored, and transmitted, ensuring that mirrored traffic flows only to authorised monitoring infrastructure."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Retention requirements mandate that Windows event logs are forwarded to protected, centralised storage before local copies can be cleared, ensuring that adversary log deletion does not eliminate the authoritative audit record."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Handling and retention policies for Linux and macOS system logs ensure that log outputs are forwarded to immutable centralised storage, preserving forensic evidence even when adversaries clear local log files on compromised hosts."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Email retention policies that maintain protected archival copies of mailbox data ensure that adversary attempts to clear mailbox contents do not permanently destroy evidence, as retained copies remain available for forensic investigation."},{"id":"T1114.001","name":"Local Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information handling controls governing local email storage—including encryption, access restrictions, and retention limits—reduce the volume of exploitable email data persisting on endpoints where adversaries could perform local email collection."},{"id":"T1114.002","name":"Remote Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Retention controls that enforce timely archival and purging of remote email stores reduce the accumulated volume of messages available for adversary collection via compromised email server access or delegated mailbox permissions."},{"id":"T1114.003","name":"Email Forwarding Rule","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Output handling controls that monitor and restrict email forwarding rule creation limit adversary ability to establish persistent email collection via auto-forwarding rules, as retention policies flag anomalous data routing configurations."},{"id":"T1213.004","name":"Customer Relationship Management Software","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information handling and retention controls governing CRM system outputs ensure that customer data exports are access-restricted, encrypted, and subject to lifecycle management, reducing the volume of sensitive data available for adversary collection."},{"id":"T1548.004","name":"Elevated Execution with Prompt","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Proper handling and retention of authorization prompt logs and elevation request records ensures that abuse of elevated execution prompts is captured in audit trails and preserved for forensic analysis according to retention requirements."},{"id":"T1550.001","name":"Application Access Token","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Information handling controls governing application access tokens—including secure storage, short expiry times, and proper revocation procedures—limit the window during which stolen tokens can be used for lateral movement or defense evasion."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Handling and retention controls for private keys mandate secure storage in hardware security modules or encrypted keystores with defined rotation schedules, reducing the likelihood that private keys persist in accessible file system locations."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information handling controls that require encryption and integrity verification of sensitive network outputs render ARP cache poisoning attacks ineffective for credential harvesting, as intercepted data remains properly protected in transit."},{"id":"T1557.004","name":"Evil Twin","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Output handling controls mandating encrypted transmission of sensitive information ensure that evil twin attacks cannot capture usable data, as properly handled information remains encrypted regardless of the wireless access point used."},{"id":"T1558.002","name":"Silver Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Retention and handling controls for service account credentials and Kerberos keytab files reduce the attack surface for silver ticket forgery by ensuring these materials are stored securely, rotated regularly, and purged when no longer required."},{"id":"T1558.003","name":"Kerberoasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Information handling controls that enforce strong encryption of service principal name credentials and mandate regular password rotation reduce the effectiveness of Kerberoasting by ensuring extracted ticket-granting service tickets resist offline cracking."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Proper handling of Kerberos pre-authentication settings and credential outputs ensures that accounts requiring pre-authentication are properly configured and that AS-REP responses containing crackable material are minimised through correct security policy enforcement."},{"id":"T1558.005","name":"Ccache Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Retention controls for Kerberos credential caches (ccache files) mandate secure storage permissions and timely purging, preventing adversaries from harvesting cached tickets that persist beyond their operational need on compromised systems."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Information handling controls that enforce integrity checksums and audit trails on stored data outputs enable detection of stored data manipulation by providing authoritative integrity baselines for comparison against potentially tampered records."},{"id":"T1565.002","name":"Transmitted Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Output handling controls that mandate integrity verification of transmitted data enable detection of in-transit data manipulation, as cryptographic checksums and digital signatures reveal unauthorized modifications to data during transmission."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Handling and retention controls for SNMP management outputs ensure that MIB dump data containing sensitive network configuration is encrypted at rest, access-restricted, and purged on schedule, limiting adversary collection opportunities."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Information output handling controls mandate that network device configuration dumps are encrypted, stored in access-controlled repositories, and retained only for the defined operational period, reducing the window for adversary collection of sensitive infrastructure data."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-013","SP-029"]}}