Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

SI-12 — Information Management and Retention

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

3Enhancements
0Parameters
4Baseline memberships
3Assessment methods

SI — System and Information Integrity · NIST SP 800-53 Release 5.2.0

LowModerateHighPrivacy
Official NIST control content

Control statement

Manage and retain information within the system and information output from the system in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines and operational requirements.

Official NIST discussion

Discussion

Information management and retention requirements cover the full life cycle of information, in some cases extending beyond system disposal. Information to be retained may also include policies, procedures, plans, reports, data output from control implementation, and other types of administrative information. The National Archives and Records Administration (NARA) provides federal policy and guidance on records retention and schedules. If organizations have a records management office, consider coordinating with records management personnel. Records produced from the output of implemented controls that may require management and retention include, but are not limited to: All XX-1, [AC-6(9)](#ac-6.9), [AT-4](#at-4), [AU-12](#au-12), [CA-2](#ca-2), [CA-3](#ca-3), [CA-5](#ca-5), [CA-6](#ca-6), [CA-7](#ca-7), [CA-8](#ca-8), [CA-9](#ca-9), [CM-2](#cm-2), [CM-3](#cm-3), [CM-4](#cm-4), [CM-6](#cm-6), [CM-8](#cm-8), [CM-9](#cm-9), [CM-12](#cm-12), [CM-13](#cm-13), [CP-2](#cp-2), [IR-6](#ir-6), [IR-8](#ir-8), [MA-2](#ma-2), [MA-4](#ma-4), [PE-2](#pe-2), [PE-8](#pe-8), [PE-16](#pe-16), [PE-17](#pe-17), [PL-2](#pl-2), [PL-4](#pl-4), [PL-7](#pl-7), [PL-8](#pl-8), [PM-5](#pm-5), [PM-8](#pm-8), [PM-9](#pm-9), [PM-18](#pm-18), [PM-21](#pm-21), [PM-27](#pm-27), [PM-28](#pm-28), [PM-30](#pm-30), [PM-31](#pm-31), [PS-2](#ps-2), [PS-6](#ps-6), [PS-7](#ps-7), [PT-2](#pt-2), [PT-3](#pt-3), [PT-7](#pt-7), [RA-2](#ra-2), [RA-3](#ra-3), [RA-5](#ra-5), [RA-8](#ra-8), [SA-4](#sa-4), [SA-5](#sa-5), [SA-8](#sa-8), [SA-10](#sa-10), [SI-4](#si-4), [SR-2](#sr-2), [SR-4](#sr-4), [SR-8](#sr-8).

Original Bare Metal Cyber perspective

From control text to operational evidence

Use Information Management and Retention as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy information handling.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • patch and remediation records
  • malware protection configuration
  • monitoring alerts and response records
  • integrity validation and exception reports

Common failure patterns

  • patch compliance hides unsupported assets
  • alerts generated without response ownership
  • exceptions never expire
  • integrity monitoring excludes critical configurations

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SI-12[01]information within the system is managed in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements;
  2. SI-12[02]information within the system is retained in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements;
  3. SI-12[03]information output from the system is managed in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements;
  4. SI-12[04]information output from the system is retained in accordance with applicable laws, Executive Orders, directives, regulations, policies, standards, guidelines, and operational requirements.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • personally identifiable information processing policy
  • records retention and disposition policy
  • records retention and disposition procedures
  • federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to information management and retention
  • media protection policy
  • media protection procedures
  • audit findings
  • system security plan
  • privacy plan
  • privacy program plan
  • personally identifiable information inventory
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel with information and records management, retention, and disposition responsibilities
  • organizational personnel with information security and privacy responsibilities
  • network administrators

Test

  • Organizational processes for information management, retention, and disposition
  • automated mechanisms supporting and/or implementing information management, retention, and disposition
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official CUI requirement crosswalk

Related NIST SP 800-171 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SI-12(1) — Limit Personally Identifiable Information Elements

Privacy

Limit personally identifiable information being processed in the information life cycle to the following elements of personally identifiable information: [Organization-defined: elements of personally identifiable information].

Official discussion

Limiting the use of personally identifiable information throughout the information life cycle when the information is not needed for operational purposes helps to reduce the level of privacy risk created by a system. The information life cycle includes information creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposition. Risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to determining which elements of personally identifiable information may create risk.

Organization-defined parameters (1)
elements of personally identifiable informationelements of personally identifiable information being processed in the information life cycle are defined;
Assessment objectives and methods

personally identifiable information being processed in the information life cycle is limited to [Organization-defined: elements of personally identifiable information].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • personally identifiable information processing policy
  • personally identifiable information processing procedures
  • records retention and disposition policy
  • records retention and disposition procedures
  • federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to limiting personally identifiable information elements
  • personally identifiable information inventory
  • system audit records
  • audit findings
  • system security plan
  • privacy plan
  • privacy program plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • data mapping documentation
  • other relevant documents or records

Interview

  • Organizational personnel with information and records management, retention, and disposition responsibilities
  • organizational personnel with security and privacy responsibilities
  • network administrators

Test

  • Organizational processes for information management and retention (including limiting personally identifiable information processing)
  • automated mechanisms supporting and/or implementing limits to personally identifiable information processing
Related controls
Official NIST control enhancement

SI-12(2) — Minimize Personally Identifiable Information in Testing, Training, and Research

Privacy

Use the following techniques to minimize the use of personally identifiable information for research, testing, or training: [Organization-defined: organization-defined techniques].

Official discussion

Organizations can minimize the risk to an individual’s privacy by employing techniques such as de-identification or synthetic data. Limiting the use of personally identifiable information throughout the information life cycle when the information is not needed for research, testing, or training helps reduce the level of privacy risk created by a system. Risk assessments as well as applicable laws, regulations, and policies can provide useful inputs to determining the techniques to use and when to use them.

Organization-defined parameters (4)
organization-defined techniques
techniquestechniques used to minimize the use of personally identifiable information for research are defined;
techniquestechniques used to minimize the use of personally identifiable information for testing are defined;
techniquestechniques used to minimize the use of personally identifiable information for training are defined;
Assessment objectives and methods
  1. SI-12(02)[01][Organization-defined: techniques] are used to minimize the use of personally identifiable information for research;
  2. SI-12(02)[02][Organization-defined: techniques] are used to minimize the use of personally identifiable information for testing;
  3. SI-12(02)[03][Organization-defined: techniques] are used to minimize the use of personally identifiable information for training.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • personally identifiable information processing policy
  • personally identifiable information processing procedures
  • federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to minimizing the use of personally identifiable information in testing, training, and research
  • policy for the minimization of personally identifiable information used in testing, training, and research
  • procedures for the minimization of personally identifiable information used in testing, training, and research
  • documentation supporting minimization policy implementation (e.g., templates for testing, training, and research)
  • data sets used for testing, training, and research
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel with information and records management, retention, and disposition responsibilities
  • organizational personnel with information security and privacy responsibilities
  • network administrators
  • system developers
  • personnel with IRB responsibilities

Test

  • Organizational processes for the minimization of personally identifiable information used in testing, training, and research
  • automated mechanisms supporting and/or implementing the minimization of personally identifiable information used in testing, training, and research
Related controls
Official NIST control enhancement

SI-12(3) — Information Disposal

Privacy

Use the following techniques to dispose of, destroy, or erase information following the retention period: [Organization-defined: organization-defined techniques].

Official discussion

Organizations can minimize both security and privacy risks by disposing of information when it is no longer needed. The disposal or destruction of information applies to originals as well as copies and archived records, including system logs that may contain personally identifiable information.

Organization-defined parameters (4)
organization-defined techniques
techniquestechniques used to dispose of information following the retention period are defined;
techniquestechniques used to destroy information following the retention period are defined;
techniquestechniques used to erase information following the retention period are defined;
Assessment objectives and methods
  1. SI-12(03)[01][Organization-defined: techniques] are used to dispose of information following the retention period;
  2. SI-12(03)[02][Organization-defined: techniques] are used to destroy information following the retention period;
  3. SI-12(03)[03][Organization-defined: techniques] are used to erase information following the retention period.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • personally identifiable information processing policy
  • personally identifiable information processing procedures
  • records retention and disposition policy
  • records retention and disposition procedures
  • laws, Executive Orders, directives, policies, regulations, standards, and operational requirements applicable to information disposal
  • media protection policy
  • media protection procedures
  • system audit records
  • audit findings
  • information disposal records
  • system security plan
  • privacy plan
  • privacy impact assessment
  • privacy risk assessment documentation
  • other relevant documents or records

Interview

  • Organizational personnel with information and records management, retention, and disposition responsibilities
  • organizational personnel with information security and privacy responsibilities
  • network administrators

Test

  • Organizational processes for information disposition
  • automated mechanisms supporting and/or implementing information disposition
Source record

Authoritative sources