Set retention according to investigation needs and data impact. Include logs, backups and support exports in the lifecycle.
Evaluation approach
Raw events, aggregates and incident evidence may warrant different periods. Cover backups and export destinations in deletion policy.
Application example
Consider retaining anonymous performance trends longer than detailed user-linked records.
Limits and considerations
Deleting from the primary system may leave copies in a SIEM or backup.
Include every copy in deletion rules
Primary-database deletion does not automatically remove exports or backups. Cover the systems and access purposes along the data flow, and verify the deletion behavior that can actually be implemented.
Distinguish necessary investigation periods from unnecessary accumulation. Review legal and contractual conditions with responsible teams. Define when links between technical events and user identities are removed.
Checks and decisions
- Map data copies
- Verify deletion
- Document evidence exceptions
Choose retention for a defined purpose with an accountable owner.
Sources
The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.