Federal Standards for Logging: Data Retention
"Tina Bird" <[email protected]>
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <035901c7bf36$014bc2f0$1701a8c0@lindesfarne> |
Hi all -- List member Rodney Thayer directed me to the Common Policy Framework of the U.S. federal government's PKI infrastructure, as an example of a clearly delineated list of events to be audited, the information required to be gathered, and data retention periods. Although it's targeted at the area of fed PKI deployments, the lists will be useful in a wide variety of environments. And it's always useful to have examples of who thinks maintaining all these logs is important, and why: http://www.cio.gov/fpkipa/documents/CommonPolicy.pdf If anyone happens to have similar mandates for other organizations or uses, I'd be delighted to know about them. I'm in the process of collecting up-to-date info on log retention periods. Enjoy! tbird