Skip to content

Log Retention

What is Log Retention?

Policies defining how long log data must be stored based on compliance requirements, security needs, and organizational policies.

Information Security

Each of these is named in at least one of the same controls as log retention. The number is how many controls name both.

What the standards actually require on log retention

Requirements naming log retention across 6 standards, quoted from the control text.

Providers must cooperate with cyberspace and other authorities' supervision and inspection, give explanations, retain relevant logs (records) for the period prescribed by law, and provide necessary technical/data support and assistance.

CN-ALG-A28 · Audit Cooperation and Log Retention
NIST SP 800-922 controls

Operate log retention per NIST SP 800-92 Chapter 4 (Planning) Section 4.5 + Chapter 5 Operational Processes. Retention policy aligned to legal and regulatory requirements: document retention period per log category (security event logs + audit logs + access lo...

NISTSP92-6 · Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold
PCI DSS 4.02 controls

Audit log history is retained for at least 12 months, with at least the most recent three months immediately available for analysis.

10.5.1 · Audit log retention 12 months

Directions 5-7 establish the technical baseline for evidence preservation + forensic readiness + time integrity. Direction 5: All service providers + intermediaries + data centres + body corporates + government organisations shall mandatorily enable logs of al...

CERTIN-Logging-180DayRetention-IndiaLocalisation-NTP-NIC-NPL-CERTIn-Access-Dir5to7 · CERT-In Directions 5-7 System Logging + Clock Synchronization - 180-Day Log Retention in India + NTP Synchronisation with NIC/NPL + Log Availability to CERT-In on Order

UR E27 requires equipment manufacturers to deliver CBS with logging + forensic readiness capabilities aligned with IEC 62443-4-2 CR 2.8-2.12 (Auditable events) + FR 6 (Timely Response to Events).

IACS-UR-E27-Logging-Forensics-EventCapture · IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection

Plan and configure log retention at each logging service according to compliance, regulatory and business requirements so logs are archived for the required period.

ASBv3-LT-6 · Configure log storage retention

Questions people ask about log retention

What is Log Retention?
Policies defining how long log data must be stored based on compliance requirements, security needs, and organizational policies.
Why is Log Retention important for compliance?
Log Retention is a key concept in Information Security. Understanding log retention helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Log Retention?
Log Retention appears in the requirement text of Administrative Measures for the Security Assessment of Generative AI Services (2023) and Algorithmic Recommendation Management Provisions (2022), NIST SP 800-92, PCI DSS 4.0, India CERT-In Cyber Security Directions 2022, IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems. Across these standards we have identified 10 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Log Retention?
Explore our compliance framework pages to see how log retention applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Log Retention applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.