# SI-12 Information Management and Retention

NIST SP 800-53 control. Family: SI System and Information Integrity. Function: preventative. Baselines: low, moderate, high, privacy. Mapping licence: CC BY-SA 4.0.

Statement: Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.
Guidance: Information management and retention requirements cover the full life cycle of information, in some cases extending beyond system disposal. Information to be retained may also include policies, procedures, plans, reports, data output from control implementation, and other types of administrative information. The National Archives and Records Administration (NARA) provides federal policy and guidance on records retention and schedules. If organizations have a records management office, consider coordinating with records management personnel. Records produced from the output of implemented controls that may require management and retention include, but are not limited to: All XX-1, AC-06(09), AT-04, AU-12, CA-02, CA-03, CA-05, CA-06, CA-07, CA-08, CA-09, CM-02, CM-03, CM-04, CM-06, CM-08, CM-09, CM-12, CM-13, CP-02, IR-06, IR-08, MA-02, MA-04, PE-02, PE-08, PE-16, PE-17, PL-02, PL-04, PL-07, PL-08, PM-05, PM-08, PM-09, PM-18, PM-21, PM-27, PM-28, PM-30, PM-31, PS-02, PS-06, PS-07, PT-02, PT-03, PT-07, RA-02, RA-03, RA-05, RA-08, SA-04, SA-05, SA-08, SA-10, SI-04, SR-02, SR-04, SR-08.

## Enhancements (3)
- SI-12(01) Limit Personally Identifiable Information Elements. Baselines: privacy
- SI-12(02) Minimize Personally Identifiable Information in Testing, Training, and Research. Baselines: privacy
- SI-12(03) Information Disposal. Baselines: privacy
Each enhancement's statement: /api/v1/controls/SI-12?fields=enhancements

## Patterns that use it (2)
- Important (1): SP-013 Data Security Pattern
- Standard (1): SP-029 Zero Trust Architecture

## Clauses by framework (56 frameworks)
- iso_27001_2022: A.5.33, A.8.10. OSA's own, not in NIST's crosswalk: A.5.33, A.8.10
- iso_27002_2022: 5.33, 8.10
- cobit_2019: APO14
- pci_dss_v4: 3.2, 3.3
- nist_csf_2: ID.AM-07, ID.AM-08
- cis_controls_v8: CIS 3, CIS 3.1, CIS 3.4, CIS 3.5
- soc2_tsc: C1.2, CC6.5, PI1.5
- iso_42001_2023: A.8.5
- bsi_grundschutz: CON.6
- anssi: Hygiene.8, Hygiene.19, SecNumCloud.9.2
- osfi_b13: B-13.3.2
- finma_circular: IV.D(78), IV.D(82), IV.E(83)
- gdpr: Art.5(1)(e), Art.5(1)(f), Art.17(1), Art.32(1)(a)
- dora: Art.8(1), Art.12(3)
- bio2: 5.33, 8.10
- rbi_csf: Annex1.15
- fisc: FISC.O9, FISC.T5
- lgpd_bcb: BCB.Art.9, BCB.Art.20, LGPD.Art.15-16
- hkma_tme1: TME1.6.5, TME1.7.2
- mlps_2: 8.1.4.11
- dnb_good_practice: DNB.12.1, DNB.12.2, DNB.12.3
- cra: CRA.I.2g, CRA.I.2m
- cbb_tm: TM-9
- cbuae: CR-5
- nca_ecc: 2-7
- cbe_csf: CTO-2
- cbn_csf: Part3.4, Part7.1
- popia: s14
- sa_js2: JS2-8.2
- bcbs_239: Principle 2, Principle 4
- bot_cyber: Ch2.3, Ch9.2
- ecb_croe: CROE.2.3.3
- ffiec_is: II.C.13, II.C.13(c)
- hipaa_sr: §164.316(b)(2)(i)
- iosco_cyber: PROT-3
- nydfs_500: 500.13, 500.18
- sebi_cscrf: DATALOC, PR.DS
- cmmc_2: SI
- cbest: CBEST.9
- tiber_eu: TIBER.CONF
- common_criteria: CC Part 2 — FDP
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.G.4
- fda_21_cfr_11: §11.10(c), §11.10(k)
- hitrust_csf: 06.b, 13.c
- lloyds_ms: BP2.2, MS1.1, MS2.1, MS5.1, MS6.1, MS7.1, MS8.7, MS13.2
- naic_ds: 4-asset, 8
- nhs_dspt: NDG-5.4
- pra_ss1_23: P3.2, P5.5
- solvency_ii: Art.49(3), DR.266-DataSec, EIOPA-Cloud-GL9, Pillar3-Reporting
- csa_ccm_v4: DSP-02, DSP-16
- csa_aicm: DSP-02, DSP-16, DSP-21, DSP-24
- ccss_v9: 2.02.1
- mica: Art.82(1)
- basel_sco60: SCO60.70, SCO60.71
- dpdpa: Act.6(1), Act.8(7), Act.12(3), Rules.6(1)(e), Rules.8(1), Rules.8(3), Rules.Sch1.B.3-4, Rules.Sch2
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SI-12
- Clauses only: /api/v1/controls/SI-12?fields=mappings
- Page for people: /controls/si-12/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
