How long do we actually need to keep logs, and who says so?

Log retention periods vary significantly across frameworks, typically ranging from 90 days to 3 years or more, driven by regulatory compliance, threat detection, and forensic analysis needs. PCI DSS mandates 1 year, with 90 days immediately available, while FedRAMP often requires 3 years for audit logs, depending on impact level. CERT-In also specifies varying periods based on log type and incident severity, generally recommending at least 180 days to 1 year for critical logs.

PCI DSS Requirement 10.7 mandates retaining audit trail history for at least one year, with at least three months immediately available for analysis. This ensures sufficient data for incident response and forensic investigations within the Cardholder Data Environment (CDE). Organisations often leverage Security Information and Event Management (SIEM) systems to centralise, correlate, and store logs efficiently, addressing both the immediate availability and long-term archival requirements. CERT-In guidelines, particularly for critical infrastructure, typically recommend retaining logs for a minimum of 180 days to 365 days, with some types of logs, such as network device configurations or access logs, potentially requiring longer retention for forensic purposes or compliance with sector-specific regulations.

FedRAMP, leveraging NIST SP 800-53 controls, generally requires audit logs to be retained for a minimum of three years for Moderate and High impact systems, aligning with control AU-11. This extended period supports comprehensive post-incident analysis, long-term trend analysis for continuous monitoring, and compliance with federal record-keeping mandates. Practitioners often err by not categorising logs effectively or failing to implement robust log management solutions that can scale to meet these retention periods, leading to compliance gaps during assessments. The specific retention duration can also depend on the system's impact level and the authorising agency's particular requirements, necessitating a thorough review of the System Security Plan (SSP) and associated policies.

Sources

  • PCI DSS v4.0, Requirement 10.7
  • NIST SP 800-53 Rev. 5, Control AU-11
  • CERT-In Guidelines for Information Security

Related