Identification data may be kept in the active base while the person is authorised; access logs generated by the device should be deleted three months after recording; identification and log data used to track working time may be kept in intermediate archive up to five years (see the CNIL HR retention reference).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.