Logging, Monitoring and Log Retention Policy
Document control
| Field | Value |
|---|---|
| Document status | Active policy document |
| Owner | Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
Define requirements for collecting, protecting, reviewing, and retaining logs required for security, operations, troubleshooting, and compliance.
Log sources
Relevant sources may include application logs, authentication logs, administrative activity, API access, system logs, network/security events, database logs, deployment logs, backup logs, and third-party service logs.
Required log fields
Where supported, logs should include timestamp, user/service identity, source, action, target resource, status/result, request identifier, and error details without exposing sensitive secrets.
Protection
Logs must be protected from unauthorized access, tampering, and unnecessary exposure of sensitive data. Secrets and personal data should not be logged unless required and protected.
Monitoring
Security-relevant alerts should be reviewed based on severity. Repeated failures, unusual access, privileged changes, and backup/job failures should be investigated.
Retention
Retention should align with contractual, operational, security, and legal requirements. Retention periods may differ by system criticality and log type.
Evidence to maintain
Logging configuration, retention settings, alert rules, review records, incident-linked logs, and exception approvals.