PCI 10.7 Retain audit trail history for at least one year - Retention method for security log

Information

Retaining logs for at least a year allows for the fact that it often takes a while to notice that a compromise has occurred or is occurring, and allows investigators sufficient log history to better determine the length of time of a potential breach and potential system(s) impacted. By having three months of logs immediately available, an entity can quickly identify and minimize impact of a data breach. Storing logs in off-line locations could prevent them from being readily available, resulting in longer time frames to restore log data, perform analysis, and identify impacted systems or data.

See Also

https://www.pcisecuritystandards.org/documents/PCI_DSS_v3.pdf

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-11, CSCv6|6.3

Plugin: Windows

Control ID: 2c09a8c26216b4bc8e7f90c8769ca643af371c21493d92031d8f7821e0ebedfb