Logo

CISOBot - Your AI CISO Assistant

MON-10

Event Log Retention

Weight: 10/10
Description

Mechanisms exist to retain event logs for a time period consistent with records retention requirements to provide support for after-the-fact investigations of security incidents and to meet statutory, regulatory and contractual retention requirements.

Control Question

Does the organization retain event logs for a time period consistent with records retention requirements to provide support for after-the-fact investigations of security incidents and to meet statutory, regulatory and contractual retention requirements?

Control Metadata
Domain:

Continuous Monitoring

Validation Cadence:

Semi-Annual

Evidence Request List:

E-AST-11

Have questions about this control?

Ask CISOBot for implementation guidance and best practices