SI-12 Information Management and Retention
System and Information Integrity
Description
Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.
Supplemental Guidance
Information management and retention requirements cover the full life cycle of information, in some cases extending beyond system disposal. Information to be retained may also include policies, procedures, plans, reports, data output from control implementation, and other types of administrative information. The National Archives and Records Administration (NARA) provides federal policy and guidance on records retention and schedules. If organizations have a records management office, consider coordinating with records management personnel. Records produced from the output of implemented controls that may require management and retention include, but are not limited to: All XX-1, AC-06(09), AT-04, AU-12, CA-02, CA-03, CA-05, CA-06, CA-07, CA-08, CA-09, CM-02, CM-03, CM-04, CM-06, CM-08, CM-09, CM-12, CM-13, CP-02, IR-06, IR-08, MA-02, MA-04, PE-02, PE-08, PE-16, PE-17, PL-02, PL-04, PL-07, PL-08, PM-05, PM-08, PM-09, PM-18, PM-21, PM-27, PM-28, PM-30, PM-31, PS-02, PS-06, PS-07, PT-02, PT-03, PT-07, RA-02, RA-03, RA-05, RA-08, SA-04, SA-05, SA-08, SA-10, SI-04, SR-02, SR-04, SR-08.
Changes from Rev 4
Title changed from 'Information Handling and Retention' Control text changes 'information handling' to 'information management' and changes the wording of the list of 'in accordance with' specifics Discussion adds recommendation to coordinate with records management personnel and references numerous other controls Incorporates data retention elements of withdrawn App J control DM-02
Enhancements (3)
What NIST adds to this control. Select one to read its statement.
SI-12(01) Limit Personally Identifiable Information Elements Privacy
Limit personally identifiable information being processed in the information life cycle to the following elements of personally identifiable information: [Assignment: organization-defined elements of personally identifiable information].
SI-12(02) Minimize Personally Identifiable Information in Testing, Training, and Research Privacy
Use the following techniques to minimize the use of personally identifiable information for research, testing, or training: [Assignment: organization-defined techniques].
SI-12(03) Information Disposal Privacy
Use the following techniques to dispose of, destroy, or erase information following the retention period: [Assignment: organization-defined techniques].
Patterns that use this control (2)
Grouped by the emphasis each pattern gives it.
Important (1)
Standard (1)
MITRE ATT&CK Techniques (34)
ATT&CK v16.1Techniques mitigated by this control, mapped via CTID.