What should investigators ask about retention?¶
Investigators should ask specific questions about what was retained, where it was retained and for how long.
A broad statement that “logs are kept for 90 days” may conceal important differences.
Avoid the dangerous assumption¶
The dangerous assumption is that one retention period applies to every log type and every storage location.
It often does not.
Authentication, audit, security, application and administrator records may each have different periods. Local devices, cloud platforms, SIEM systems, archives and backups may all retain different copies.
Ask which event types were generated, the normal retention period for each and whether the limit was based on age, storage volume or subscription level.
Ask whether records were deleted, archived, compressed, moved to cold storage or merely removed from the normal dashboard. Establish whether legal hold, incident hold or manual export functions existed.
The relevant question is historical: what policy and configuration applied when the event occurred and when the request was made? Current settings may not answer that.
Investigators should also ask whether retention changed after an upgrade, downgrade, incident or policy decision. Record the date of any change and whether older records were affected immediately or only prospectively.
Where the source period has expired, ask whether the same data was forwarded to another system, included in backups, retained by a managed service or preserved by a provider. Avoid assuming all copies expired together.
Ask who can authoritatively explain the policy and whether technical behaviour matched the written policy. A stated period may differ from actual availability because of storage faults, licensing or failed collection.
Operational takeaway¶
Retention enquiries should identify the specific log type, storage location, historical policy, licence, archive and alternative copies rather than relying on one headline retention period.