Batch Register

Audit log retention and archive

None of the held texts sets a fixed period on this consumer; every row below reads no period set by the text. Paste one job that feeds this consumer, for example audit_log_archive, weekly, and the register reads its period against the clocks below, names the gap in hours, and carries the question for its owner.

Matched on the job name or the consumer column by these words: log archive, log retention, log rotation, archive logs, log purge, log archive.

The clock each rule sets

RegimeClockClause
PCI DSSno clockPCI DSS 10.5.1 Audit log retention 12 monthstwelve months retained, three immediately available; no run period
ISO 27001no clockISO 27001 8.15 Logging

Questions this page answers

How often does PCI DSS v4.0 require audit log retention and archive?

The held text of PCI DSS 10.5.1 (Audit log retention 12 months) sets no fixed period: twelve months retained, three immediately available; no run period. Audit log history is retained for at least 12 months, with at least the most recent three months immediately available for analysis.

How often does ISO/IEC 27001:2022 require audit log retention and archive?

The held text of ISO 27001 8.15 (Logging) sets no fixed period: no period set by the text. Produce, store, protect and analyse logs of activities, exceptions and faults.

What does the register ask the owner of a audit log retention and archive job?

Does the archive keep twelve months, with the latest three months readable without a restore?

The clauses in full

PCI DSS 10.5.1 Audit log retention 12 monthsthe standard's page

Audit log history is retained for at least 12 months, with at least the most recent three months immediately available for analysis.

What an assessor asks to see: SIEM retention policy configuration; Hot storage configuration for last 3 months; Cold storage location and accessibility evidence; Sample log restoration test results. Where it usually falls short: Retention below 12 months

ISO 27001 8.15 Loggingthe standard's page

Produce, store, protect and analyse logs of activities, exceptions and faults.

Guidance beside it, ISO 27002 8.15: Requires logs to be produced, stored, protected and analysed, covering activities, exceptions, faults and any other event of relevance. Older source material adds that records of user activity, exceptions and security events should be retained for an agreed period to support later investigation and access control monitoring, and that faults should be logged, analysed and acted on.

What an assessor asks to see: log_collection_policy; log_storage_and_protection; log_review_and_analysis; log_retention_and_disposal. Where it usually falls short: Inconsistent log collection across systems

Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Run this job through the register