Android and iOS

Retention periods for RASP events

Latency, availability, incident response and protection policies.

Production operations1 min readEditorial methods

Set retention according to investigation needs and data impact. Include logs, backups and support exports in the lifecycle.

Evaluation approach

Raw events, aggregates and incident evidence may warrant different periods. Cover backups and export destinations in deletion policy.

Application example

Consider retaining anonymous performance trends longer than detailed user-linked records.

Limits and considerations

Deleting from the primary system may leave copies in a SIEM or backup.

Include every copy in deletion rules

Primary-database deletion does not automatically remove exports or backups. Cover the systems and access purposes along the data flow, and verify the deletion behavior that can actually be implemented.

Distinguish necessary investigation periods from unnecessary accumulation. Review legal and contractual conditions with responsible teams. Define when links between technical events and user identities are removed.

Checks and decisions

  • Map data copies
  • Verify deletion
  • Document evidence exceptions

Choose retention for a defined purpose with an accountable owner.

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.