Control statement
Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.
Discussion
Information management and retention requirements cover the full life cycle of information, in some cases extending beyond system disposal. Information to be retained may also include policies, procedures, plans, reports, data output from control implementation, and other types of administrative information. The National Archives and Records Administration (NARA) provides federal policy and guidance on records retention and schedules. If organizations have a records management office, consider coordinating with records management personnel. Records produced from the output of implemented controls that may require management and retention include, but are not limited to: All XX-1, [AC-6(9)](#ac-6.9), [AT-4](#at-4), [AU-12](#au-12), [CA-2](#ca-2), [CA-3](#ca-3), [CA-5](#ca-5), [CA-6](#ca-6), [CA-7](#ca-7), [CA-8](#ca-8), [CA-9](#ca-9), [CM-2](#cm-2), [CM-3](#cm-3), [CM-4](#cm-4), [CM-6](#cm-6), [CM-8](#cm-8), [CM-9](#cm-9), [CM-12](#cm-12), [CM-13](#cm-13), [CP-2](#cp-2), [IR-6](#ir-6), [IR-8](#ir-8), [MA-2](#ma-2), [MA-4](#ma-4), [PE-2](#pe-2), [PE-8](#pe-8), [PE-16](#pe-16), [PE-17](#pe-17), [PL-2](#pl-2), [PL-4](#pl-4), [PL-7](#pl-7), [PL-8](#pl-8), [PM-5](#pm-5), [PM-8](#pm-8), [PM-9](#pm-9), [PM-18](#pm-18), [PM-21](#pm-21), [PM-27](#pm-27), [PM-28](#pm-28), [PM-30](#pm-30), [PM-31](#pm-31), [PS-2](#ps-2), [PS-6](#ps-6), [PS-7](#ps-7), [PT-2](#pt-2), [PT-3](#pt-3), [PT-7](#pt-7), [RA-2](#ra-2), [RA-3](#ra-3), [RA-5](#ra-5), [RA-8](#ra-8), [SA-4](#sa-4), [SA-5](#sa-5), [SA-8](#sa-8), [SA-10](#sa-10), [SI-4](#si-4), [SR-2](#sr-2), [SR-4](#sr-4), [SR-8](#sr-8).
From control text to operational evidence
Use Information Management and Retention as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy information handling.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- patch and remediation records
- malware protection configuration
- monitoring alerts and response records
- integrity validation and exception reports
Common failure patterns
- patch compliance hides unsupported assets
- alerts generated without response ownership
- exceptions never expire
- integrity monitoring excludes critical configurations
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- SI-12[01]information within the system is managed in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements;
- SI-12[02]information within the system is retained in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements;
- SI-12[03]information output from the system is managed in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements;
- SI-12[04]information output from the system is retained in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements.
Examine
- System and information integrity policy
- system and information integrity procedures
- personally identifiable information processing policy
- records retention and disposition policy
- records retention and disposition procedures
- federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to information management and retention
- media protection policy
- media protection procedures
- audit findings
- system security plan
- privacy plan
- privacy program plan
- personally identifiable information inventory
- privacy impact assessment
- privacy risk assessment documentation
- other relevant documents or records
Interview
- Organizational personnel with information and records management, retention, and disposition responsibilities
- organizational personnel with information security and privacy responsibilities
- network administrators
Test
- Organizational processes for information management, retention, and disposition
- automated mechanisms supporting and/or implementing information management, retention, and disposition
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related NIST SP 800-171 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
SI-12(1) — Limit Personally Identifiable Information Elements
Limit personally identifiable information being processed in the information life cycle to the following elements of personally identifiable information: [Organization-defined: elements of personally identifiable information].
Official discussion
Limiting the use of personally identifiable information throughout the information life cycle when the information is not needed for operational purposes helps to reduce the level of privacy risk created by a system. The information life cycle includes information creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposition. Risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to determining which elements of personally identifiable information may create risk.
Organization-defined parameters (1)
Assessment objectives and methods
personally identifiable information being processed in the information life cycle is limited to [Organization-defined: elements of personally identifiable information].
Examine
- System and information integrity policy
- system and information integrity procedures
- personally identifiable information processing policy
- personally identifiable information processing procedures
- records retention and disposition policy
- records retention and disposition procedures
- federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to limiting personally identifiable information elements
- personally identifiable information inventory
- system audit records
- audit findings
- system security plan
- privacy plan
- privacy program plan
- privacy impact assessment
- privacy risk assessment documentation
- data mapping documentation
- other relevant documents or records
Interview
- Organizational personnel with information and records management, retention, and disposition responsibilities
- organizational personnel with security and privacy responsibilities
- network administrators
Test
- Organizational processes for information management and retention (including limiting personally identifiable information processing)
- automated mechanisms supporting and/or implementing limits to personally identifiable information processing
Related controls
SI-12(2) — Minimize Personally Identifiable Information in Testing, Training, and Research
Use the following techniques to minimize the use of personally identifiable information for research, testing, or training: [Organization-defined: organization-defined techniques].
Official discussion
Organizations can minimize the risk to an individual’s privacy by employing techniques such as de-identification or synthetic data. Limiting the use of personally identifiable information throughout the information life cycle when the information is not needed for research, testing, or training helps reduce the level of privacy risk created by a system. Risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to determining the techniques to use and when to use them.
Organization-defined parameters (4)
Assessment objectives and methods
- SI-12(02)[01][Organization-defined: techniques] are used to minimize the use of personally identifiable information for research;
- SI-12(02)[02][Organization-defined: techniques] are used to minimize the use of personally identifiable information for testing;
- SI-12(02)[03][Organization-defined: techniques] are used to minimize the use of personally identifiable information for training.
Examine
- System and information integrity policy
- system and information integrity procedures
- personally identifiable information processing policy
- personally identifiable information processing procedures
- federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to minimizing the use of personally identifiable information in testing, training, and research
- policy for the minimization of personally identifiable information used in testing, training, and research
- procedures for the minimization of personally identifiable information used in testing, training, and research
- documentation supporting minimization policy implementation (e.g., templates for testing, training, and research)
- data sets used for testing, training, and research
- system security plan
- privacy plan
- privacy impact assessment
- privacy risk assessment documentation
- other relevant documents or records
Interview
- Organizational personnel with information and records management, retention, and disposition responsibilities
- organizational personnel with information security and privacy responsibilities
- network administrators
- system developers
- personnel with IRB responsibilities
Test
- Organizational processes for the minimization of personally identifiable information used in testing, training, and research
- automated mechanisms supporting and/or implementing the minimization of personally identifiable information used in testing, training, and research
Related controls
SI-12(3) — Information Disposal
Use the following techniques to dispose of, destroy, or erase information following the retention period: [Organization-defined: organization-defined techniques].
Official discussion
Organizations can minimize both security and privacy risks by disposing of information when it is no longer needed. The disposal or destruction of information applies to originals as well as copies and archived records, including system logs that may contain personally identifiable information.
Organization-defined parameters (4)
Assessment objectives and methods
- SI-12(03)[01][Organization-defined: techniques] are used to dispose of information following the retention period;
- SI-12(03)[02][Organization-defined: techniques] are used to destroy information following the retention period;
- SI-12(03)[03][Organization-defined: techniques] are used to erase information following the retention period.
Examine
- System and information integrity policy
- system and information integrity procedures
- personally identifiable information processing policy
- personally identifiable information processing procedures
- records retention and disposition policy
- records retention and disposition procedures
- laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to information disposal
- media protection policy
- media protection procedures
- system audit records
- audit findings
- information disposal records
- system security plan
- privacy plan
- privacy impact assessment
- privacy risk assessment documentation
- other relevant documents or records
Interview
- Organizational personnel with information and records management, retention, and disposition responsibilities
- organizational personnel with information security and privacy responsibilities
- network administrators
Test
- Organizational processes for information disposition
- automated mechanisms supporting and/or implementing information disposition
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.