Why it matters
Records (financial, HR, security logs) need to survive as long as required and be genuinely protected, not just backed up.
How a self-led small team implements it
Confirm your retention periods per record type and that backups actually cover them.
What auditors expect to see
Records retention schedule.
Track A.5.33 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS