Every authentication, authorisation decision, admin action, config change, approval, and evidence
write. Logs form a SHA-256 hash-chain (WORM) - tampering is detectable.
The operational audit trail is retained 90 days hot / 1 year cold (rolling). Compliance-relevant
evidence is retained per framework (often 3-7 years). Do not purge logs outside the retention policy.
Grant auditors read-only access to the audit area. Never edit or delete audit records; if a
correction is needed, append a clarifying record - never overwrite history.
On any incident or legal hold: snapshots, logs, tickets, and hashes for the affected window.
Chain of custody starts the moment you touch evidence.
standpoint it didn't happen.