Skip to main content

Management / Logging / Threats / DEV

Log Retention Policy Evasion or Misconfiguration

CCC.Logging.TH05

Log data is deleted prematurely or retained longer than legally required due to misconfigured retention policies, manual overrides, or evasion tactics. This can lead to non-compliance with regulatory requirements or loss of critical forensic evidence.

Related Capabilities

IDTitleDescription
CCC.Logging.CP07Immutable StorageAbility to prevent unauthorized alteration or deletion of logs, ensuring their integrity for auditing and forensic purposes.
CCC.Logging.CP08Retention PoliciesAbility to define and enforce granular retention periods for different log types based on regulatory requirements and internal policies.
CCC.Logging.CP12Log ArchivingAbility to archive logs that are no longer needed but must be retained.

Related Controls

IDTitleDescription
CCC.Logging.CN02Enforce Data Retention Policy for LogsEnsure that the retention period configured for logs aligns with the organization's data retention policy.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1070.004Indicator Removal on Host: File Deletion
MITRE-ATT&CKT1485Data Destruction
MITRE-ATT&CKT1562.008Impair Defenses: Disable Cloud Logs