CCI-000167
CCI-000167 Definition
| Status | |
| Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
Determine if audit records are retained for [AU-11_ODP; a time period to retain audit records that is consistent with the records retention policy is defined] to provide support for after-the-fact investigations of incidents and to meet regulatory and Organizational information retention requirements.
Validation Procedures
Examine: [SELECT FROM: Audit and accountability policy; system security plan; privacy plan; audit record retention policy and procedures; security plan; organization-defined retention period for audit records; audit record archives; audit logs; audit records; other relevant documents or records]. Interview: [SELECT FROM: Organizational personnel with audit record retention responsibilities; organizational personnel with information security and privacy responsibilities; system/network administrators].