Log Retention
What is Log Retention?
Policies defining how long log data must be stored based on compliance requirements, security needs, and organizational policies.
Terms that appear alongside log retention
Each of these is named in at least one of the same controls as log retention. The number is how many controls name both.
- integrity 14 shared controls
- audit 12 shared controls
- nist 9 shared controls
- authentication 7 shared controls
- log management 6 shared controls
- audit trail 6 shared controls
- chain of custody 6 shared controls
- authorization 5 shared controls
Frameworks that govern log retention
What the standards actually require on log retention
Requirements naming log retention across 6 standards, quoted from the control text.
Providers must cooperate with cyberspace and other authorities' supervision and inspection, give explanations, retain relevant logs (records) for the period prescribed by law, and provide necessary technical/data support and assistance.
CN-ALG-A28 · Audit Cooperation and Log Retention →Operate log retention per NIST SP 800-92 Chapter 4 (Planning) Section 4.5 + Chapter 5 Operational Processes. Retention policy aligned to legal and regulatory requirements: document retention period per log category (security event logs + audit logs + access lo...
NISTSP92-6 · Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold →Audit log history is retained for at least 12 months, with at least the most recent three months immediately available for analysis.
10.5.1 · Audit log retention 12 months →Directions 5-7 establish the technical baseline for evidence preservation + forensic readiness + time integrity. Direction 5: All service providers + intermediaries + data centres + body corporates + government organisations shall mandatorily enable logs of al...
CERTIN-Logging-180DayRetention-IndiaLocalisation-NTP-NIC-NPL-CERTIn-Access-Dir5to7 · CERT-In Directions 5-7 System Logging + Clock Synchronization - 180-Day Log Retention in India + NTP Synchronisation with NIC/NPL + Log Availability to CERT-In on Order →UR E27 requires equipment manufacturers to deliver CBS with logging + forensic readiness capabilities aligned with IEC 62443-4-2 CR 2.8-2.12 (Auditable events) + FR 6 (Timely Response to Events).
IACS-UR-E27-Logging-Forensics-EventCapture · IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection →Plan and configure log retention at each logging service according to compliance, regulatory and business requirements so logs are archived for the required period.
ASBv3-LT-6 · Configure log storage retention →Questions people ask about log retention
What is Log Retention?
Why is Log Retention important for compliance?
Which compliance frameworks address Log Retention?
Where can I learn more about Log Retention?
See how Log Retention applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.