Retention considerations for audit purposes

Posted by bluecopp3r@reddit | sysadmin | View on Reddit | 10 comments

Greetings all.

I have 2 situations I'd like your input on.

  1. I had a recent internal audit as part of our ISO 9001 processes. The backup process was audited and a few areas for improvement were identified and corrected. On review of the corrective actions the auditor asked if there would be a need to preserve backup activity logs for an extended period to show to external auditors that backups have been taking place and not just a recent activity. I have backup activity logs in Veeam set to 90 days.

For those who are in an environment that goes through audits, is there a need to retain backup activity logs? If so what is your defined retention period and what was the deciding factor(s).

  1. Having disabled accounts of former employees can pose risks by an attacker activating them and using them for lateral movement or escalating privileges. I have seen recommendations to automate the deletion of disabled accounts after a set period of time (ex. 90 days). I have also seen where admins don't delete accounts for auditing purposes.

Does removing all group membership a good enough defense for keeping disabled accounts for years? For those who don't delete accounts for auditing purposes, is this for all accounts or for specific roles or access privileges?