A.5.33 Protection of Records
Control Objective
Records shall be protected from loss, destruction, falsification, unauthorised access and unauthorised release.
Policy Statement
anDREa enforces rigorous technical and administrative safeguards to protect organizational, compliance, and user records from unauthorized modifications, premature destruction, or data leaks.
Record Protection Framework
To guarantee the confidentiality, integrity, and availability of sensitive records, anDREa integrates the following lifecycle controls:
- Inventory and Classification: All data processing operations and the records they generate are logged within the Record of Processing Activities (ROPA). The ROPA explicitly defines specific retention periods and tailored security requirements for each information system.
- Access Governance: Access to systems containing sensitive records is restricted using strict role-based access controls and identity management baselines (see: A.05.15 - Access control).
- Cryptographic Safeguards: To prevent unauthorized release or falsification, records are encrypted both at rest and in transit using industry-standard cryptographic algorithms (see: A.08.25 - Secure development life cycle).
- Platform Security: All proprietary SaaS applications developed and maintained by anDREa are engineered, deployed, and supported under secure lifecycle practices (see: Clause 7 - Support).