Organizational Control: Information Handling And Retention

Control ID: SI-12 Information Handling And Retention Family: System and Information Integrity Source: NIST 800-53r4
Control: The organization handles and retains information within the information system and information output from the system in accordance with applicable state and federal laws, Executive Orders, directives, policies, regulations, standards, and operational requirements.
Supplemental Guidance:
Information handling and retention requirements cover the full life cycle of information, in some cases extending beyond the disposal of information systems. The National Archives and Records Administration provides guidance on records retention.

Related Controls: AU-11, MP-2, MP-4, AC-16, AU-5
Control Enhancements: N/A
References: N/A
Mechanisms:
Protocol Implementation Conformance Statements: N/A