Information
Audit logs may no longer be available when needed if they are not retained for a sufficient time. Increased log retention time gives an agency the necessary visibility to investigate incidents that occurred some time ago. OMB M-21-13, Appendix C, Table 5 specifically calls out Unified Audit Logs in the Cloud Azure log category.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
See the following implementation steps to [create an audit retention policy](https://github.com/cisagov/ScubaGear/tree/v1.5.0/PowerShell/ScubaGear/baselines/defender.md#msdefender62v1-instructions) for additional guidance.