NIST SP 800-92
Log Retention and Disposition

NIST SP 800-92 NISTSP92-6: Log Retention: Policy, Tiered Storage, Backup, Secure Disposal, Legal Hold

Operate log retention per NIST SP 800-92 Chapter 4 (Planning) Section 4.5 + Chapter 5 Operational Processes. Retention policy aligned to legal and regulatory requirements: document retention period per log category (security event logs + audit logs + access logs + system logs + application logs + privacy event logs) matching the longest applicable obligation (regulatory + contractual + investigative + organisational policy). Online vs archive storage tiers: hot storage for incident response horizon (typically 30-90 days online) + warm for routine investigation (typically 1 year) + cold archive for long-term compliance (3+ years up to indefinite for some regulators) + balance cost + retrieval time + integrity guarantee per tier. Backup and recoverability of log data: replicate or back up logs to a separate facility or storage class + test recovery + measure RTO for log data + protect against ransomware and insider threats targeting log infrastructure. Secure disposal of logs at end of retention per NIST SP 800-88: apply Clear / Purge / Destroy methods per media type with documented chain of custody and Certificate of Sanitization. Legal hold and eDiscovery support: implement legal hold flagging that suspends scheduled disposal + supports eDiscovery review workflow + preserves chain of custody + integrates with legal case management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 59 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

IEC 62443 · 3 controls

  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 1800-32 · 3 controls

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery

NIST SP 800-53 Rev 5 · 2 controls

  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing

South Korea ISMS-P · 2 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • 4.4.8 Business Continuity and Recovery
  • DIQ-1 Data Integration and Interoperability
  • FFIEC-12 Disaster recovery procedures

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup

ISO/IEC 27043:2015 · 1 control

  • ISO27043-23 Backup and recovery procedures

ISO/SAE 21434 · 1 control

  • ISO21434-23 Backup and recovery procedures
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 1 control

OWASP ASVS · 1 control

OWASP MASVS · 1 control

  • OWASPMASVS-7 MASVS-RESILIENCE: Resilience Against Reverse Engineering

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 59 it maps to, and the evidence behind each claim, over MCP and REST.