Prompt
Log retention 90 days compliance
Latest observation
A 90-day log retention compliance requirement usually means your organization must collect, protect, and be able to retrieve logs for at least 90 days. Exact obligations depend on the regulation or standard, but the core controls are similar.
What “compliant” typically means
You should be able to show that logs are:
- Retained for 90 days minimum
- Protected from tampering or unauthorized deletion
- Accurately time-stamped
- Searchable and retrievable on demand
- Stored with access controls and audit trails
- Backed up or replicated to avoid loss
Common log types to retain
Typically includes logs for:
- Authentication and access events
- Administrative actions
- System and application events
- Security alerts/incidents
- Network/device activity
- Database activity, if relevant
- Cloud audit logs, if applicable
Good practice controls
To meet the requirement, organizations often implement:
-
Centralized logging
- Send logs to a SIEM or log platform
- Avoid relying only on local machine logs
-
Immutable or write-once storage
- Use WORM, object lock, or equivalent controls
- Prevent deletion or modification during retention period
-
Defined retention policy
- Explicitly state 90-day minimum retention
- Include who can access logs and how deletion occurs after retention
-
Time synchronization
- Use NTP or equivalent across systems
- Ensure logs have consistent timestamps
-
Access control
- Limit who can view, export, or delete logs
- Log all access to the log store itself
-
Monitoring and alerting
- Alert on logging failures, gaps, or retention policy violations
-
Backup and disaster recovery
- Ensure logs remain available even if primary systems fail
Evidence auditors often ask for
Be ready to provide:
- Written log retention policy
- Configuration screenshots or export showing 90-day retention
- Proof of centralized logging
- Sample logs with timestamps
- Access control lists or role permissions
- Audit trail showing log deletion controls
- Incident or monitoring evidence for logging failures
Important note
Some regulations require more than 90 days, or:
- 90 days hot / searchable
- Longer total archival retention
- Longer retention for specific log types
So you should verify the exact source of the requirement.
If you want, I can help you turn this into a policy statement, control checklist, or a compliance evidence template.