What is logged

Every authentication, authorisation decision, admin action, config change, approval, and evidence

write. Logs form a SHA-256 hash-chain (WORM) - tampering is detectable.

Retention

The operational audit trail is retained 90 days hot / 1 year cold (rolling). Compliance-relevant

evidence is retained per framework (often 3-7 years). Do not purge logs outside the retention policy.

Monitoring duties

Auditor access

Grant auditors read-only access to the audit area. Never edit or delete audit records; if a

correction is needed, append a clarifying record - never overwrite history.

What you must preserve

On any incident or legal hold: snapshots, logs, tickets, and hashes for the affected window.

Chain of custody starts the moment you touch evidence.

standpoint it didn't happen.

← Administrator Guide  ·  All guidelines