Retention Policy
Definition
An organisation's rule specifying how long log data is stored before deletion or archiving. Policies are typically driven by compliance requirements and storage cost. Short retention windows create gaps in the forensic record when incidents are discovered late.
- Field
- Log management and SIEM
- Drivers
- Compliance requirements and storage cost
- Risk
- Short windows create gaps in the forensic record
- Applies to
- Firewall, server, application, and endpoint logs
Common questions
What happens forensically when an incident is discovered after the retention window closes?+
Logs covering the initial compromise or lateral movement may already be purged, forcing investigators to rely on secondary artefacts such as backups, endpoint forensic residue, or third-party telemetry to reconstruct the earlier activity.
Do compliance frameworks mandate a specific retention period?+
Requirements vary by framework and data type; some standards set minimum periods such as one year for certain log categories, while others leave the duration to organisational risk assessment, so the applicable framework must be checked rather than assumed.
Is a longer retention policy always better for investigations?+
Longer retention improves investigative reach but raises storage cost and can itself become a compliance liability if the organisation retains sensitive data longer than a stated privacy policy permits, so the policy balances competing risks rather than maximising duration alone.
Related terms
- Alert Triage
- The process of reviewing SIEM-generated alerts to determine which are genuine security events and which are false positives. In forensic investigations, alert...
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Log Correlation
- The process of matching related events from different log sources using shared attributes such as IP address, username, timestamp, or session ID....
- Normalisation
- The process of converting log data from different vendors and formats into a common schema so that fields can be compared across...
- SIEM
- Security Information and Event Management. A platform that ingests log streams from multiple sources, normalises them to a common schema, and applies...