Skip to content
Skip to main content
Logs, Records & Provider Evidence Operational Explainer

What should investigators ask about retention?

Ask about each specific log type, storage location and historical period. A headline statement such as “90 days” may not cover all records, copies or conditions.

Define what the limit measures

Establish which events were generated and whether retention is based on age, capacity, licence or configuration. Ask whether expired data is deleted, archived, compressed or merely removed from the dashboard, and whether hold or manual export functions existed.

Authentication, audit and security data can differ across source devices, cloud systems, SIEMs, archives and backups. Copies need not expire together.

Reconstruct the policy that actually applied

Record settings at event time and request time, plus upgrades, downgrades and policy changes and whether they affected existing records. Identify an authoritative owner and compare written policy with actual technical availability, including collection faults.

Where the primary period has expired, ask about forwarding, managed services, provider preservation and backups. Frame the answer by record and location rather than assuming one organisation-wide retention rule.

The point to remember

Retention enquiries must be specific to event type, copy, historical configuration and the mechanism that removes access.

Reference: LOG-131Logs, Records & Provider Evidence