Which incident records should be retained, and for how long?
Preserve the event report, , classification and escalation decisions, response actions, communications, notification records, recovery validation, incident report, lessons learned, and linked evidence needed to reconstruct the case. Maintain an for oversight and trend analysis. Raw telemetry, working notes, malware samples, exports, and forensic images can need different storage, access, and retention rules.
ISO/IEC 27035 does not set a universal number of days or years. Define retention by record purpose, investigation and operational need, applicable law and contracts, privacy and employment rules, limitation periods, insurance terms, and litigation or regulatory holds. A hold is an authorized instruction that suspends ordinary disposal for specified material. Document which rule wins when periods conflict.
- Document record category, purpose, owner, storage, access, integrity control, retention trigger, period, disposal method, and hold process.
- Minimize personal or sensitive data while retaining what the justified purpose requires.
- Review retention rules after legal changes, new services or suppliers, investigations, exercises, and lessons learned.
ISO/IEC 27035-1 frames incident management as preparation, detection, reporting, assessment, and response, which supports keeping retained logs tied to the incident process.
ISO/IEC 27035-2 supports planning, preparation, and lessons-learned records that retained logs should preserve for incident response review.