Federal Standards for Logging: Data Retention

"Tina Bird" <[email protected]>
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <035901c7bf36$014bc2f0$1701a8c0@lindesfarne>
Hi all --

List member Rodney Thayer directed me to the Common Policy Framework of the
U.S. federal government's PKI infrastructure, as an example of a clearly
delineated list of events to be audited, the information required to be
gathered, and data retention periods. Although it's targeted at the area of
fed PKI deployments, the lists will be useful in a wide variety of
environments. And it's always useful to have examples of who thinks
maintaining all these logs is important, and why:

http://www.cio.gov/fpkipa/documents/CommonPolicy.pdf

If anyone happens to have similar mandates for other organizations or uses,
I'd be delighted to know about them. I'm in the process of collecting
up-to-date info on log retention periods.

Enjoy!

tbird
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.