A security architect at a financial services firm is developing a new enterprise-wide log retention policy. The IT operations team wants to limit retention to 90 days to control storage costs, while the legal department insists on a 7-year retention for all logs for e-discovery purposes. The security team requires at least one year of data for forensic analysis. Which of the following should be the architect's primary guiding principle when creating this policy?
To standardize log formats across all systems before defining any retention periods
To balance security monitoring needs, compliance requirements, and storage constraints
To implement the IT operations team's proposal to minimize immediate operational expenses
To prioritize the legal department's requirements to ensure maximum compliance and litigation support
The primary purpose of establishing log retention policies is to balance security, compliance, and operational needs. Log retention policies define how long different types of log data should be stored before being archived or deleted. This involves negotiating a compromise between stakeholders, such as the IT, legal, and security departments, rather than prioritizing one team's needs over all others. These policies ensure that logs are available for security incident investigation, compliance with regulatory requirements (such as PCI DSS, HIPAA, or SOX), and legal proceedings. At the same time, they help manage storage costs and system performance. Prioritizing only legal requirements can lead to excessive costs, while prioritizing only storage savings can introduce significant security and compliance risks.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why are compliance requirements important when creating a log retention policy?
Open an interactive chat with Bash
How does log retention impact storage management in an organization?
Open an interactive chat with Bash
What role do logs play in security incident investigations?
Open an interactive chat with Bash
ISC2 CISSP
Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .