Slide 14
Slide 14 text
General standard: 90 accessible/searchable, 365 retrievable.
• Business Transaction & Incident
• 7+ years
• Business Document (e.g. Email)
• Incident Archive (e.g. evidence, forensic report, tracing email, chat record)
• Alert
• 3 years (ISO27001 & NIST-800-53)
• Archived alerts with related raw logs
• Events & Server Log
• 1 year
• Server Log (KAVIAA; Key-in Log, Audit Log, Vulnerability, Integrity, Account, Antivirus)
• Traffic Log
• 92 Days (NIST CSF DE.AE Security Logging Standard 4.4.a)
• Metadata without PCAP (e.g. Traffic Log, Syslog, Threat Log)
14
>