Contact us today.Phone: +1 888 776-9234Email: sales@plurilock.com

How long must I retain audit logs and security records?

Record retention is a critical compliance requirement under CPCSC, balancing the need for historical security visibility with practical storage constraints. Organizations handling specified information must maintain comprehensive documentation and audit trails that can support incident investigation, demonstrate compliance during assessments, and satisfy legal and regulatory obligations. Understanding retention requirements helps executives plan appropriate infrastructure investments and develop compliant records management policies.

Answer

CPCSC requires retaining audit logs for at least 90 days online, with 1-2 years archival recommended for incident investigation.

ITSP.10.171 Retention Requirements

The standard requires retaining audit records for time periods consistent with organizational records retention policies, without prescribing specific durations. This flexibility allows organizations to tailor retention based on their risk profile, contractual obligations, and operational needs.

However, the standard assumes retention periods will be formally defined through organization-defined parameters (ODPs), documented in security plans, and consistently enforced. While ITSP.10.171 doesn't mandate specific periods, it references Treasury Board directives and guidelines that inform retention policies.

Organizations must document their chosen retention periods and justify them based on risk assessments, legal requirements, and operational considerations. During Level 2 assessments, assessors will examine whether documented retention policies exist, whether they're reasonable given the organization's risk profile, and whether they're actually enforced through technical controls and operational procedures.

Minimum Recommended Retention Periods

While organizations have flexibility, cybersecurity best practices and regulatory precedents suggest minimum retention periods:

  • Audit logs should be retained for at least 90 days in immediately accessible online storage to support real-time security monitoring and near-term incident investigation
  • Extended log retention of 1-2 years in archival storage provides historical visibility for investigating sophisticated attacks that often aren't discovered immediately—industry data shows the median time to detect breaches exceeds 200 days
  • Security documentation including policies, procedures, system security plans, risk assessments, and assessment reports should be retained for at least three years to cover multiple assessment cycles and demonstrate continuous compliance
  • Incident response records documenting security incidents, investigations, and remediation should be retained for at least five years given potential legal proceedings and regulatory inquiries
  • Personnel security records including training certificates, background check documentation, and access authorization records should be retained for at least two years after personnel departure per privacy law requirements
  • Configuration management records documenting system changes, approvals, and security impact analyses should be retained for the life of the system plus one year to support troubleshooting and compliance reviews

Legal and Regulatory Considerations

Multiple legal frameworks influence retention requirements. The Treasury Board Directive on Security Management establishes baseline records management requirements for federal government operations that often flow to contractors through contract clauses.

Privacy legislation including federal privacy laws requires retaining personal information used for administrative decisions for at least two years following last administrative use, affecting personnel records, access logs containing user identities, and incident records involving individuals. Provincial privacy laws may impose additional retention requirements depending on jurisdictions where contractors operate.

Contract-specific requirements may specify longer retention periods than baseline standards—organizations must review each contract involving specified information for explicit retention obligations. Industry-specific regulations in sectors like healthcare, finance, or energy may mandate longer retention for certain record types.

Litigation hold requirements can suspend normal retention schedules when legal proceedings are anticipated or underway, requiring preservation of potentially relevant records. Organizations should engage legal counsel to identify all applicable retention obligations and ensure policies satisfy them.

Records Requiring Retention

Organizations must retain multiple categories of security-relevant records. Audit logs and security event data capture the following:

  • Who accessed what specified information when
  • Privileged actions by administrative users
  • Security tool alerts and detections
  • Authentication and authorization events
  • Configuration changes
  • Network activity

Security documentation includes the following records:

  • System security plans describing security implementations
  • Policies and procedures governing security practices
  • Risk assessment reports identifying and analyzing threats
  • Security assessment reports from internal and external reviews
  • Plan of Action and Milestones (POA&M) documenting remediation efforts
  • Security authorization decisions approving system operation

Incident response records document the following information:

  • Detected incidents with timelines
  • Investigation findings and forensic evidence
  • Containment and remediation actions
  • Notifications to authorities and affected parties
  • Lessons learned and corrective actions

Personnel security records include the following documentation:

  • Training completion certificates
  • Background check results and renewals
  • Security clearances and eligibility determinations
  • Access authorization approvals
  • Non-disclosure agreements

Configuration management records document the following items:

  • Baseline configurations
  • Approved change requests
  • Security impact analyses for changes
  • Configuration audits verifying compliance

Each category serves specific purposes for security operations, compliance demonstration, and incident investigation.

Storage and Protection Requirements

Retained records must be protected with security controls appropriate to their sensitivity. Audit logs containing specified information must receive the same confidentiality protections as the specified information itself, including encryption at rest and in transit, access controls limiting viewing to authorized security personnel, and protection from unauthorized modification or deletion.

Integrity protection through write-once storage, cryptographic signatures, or blockchain-style chaining ensures records remain tamper-proof and trustworthy as evidence. Availability and backup requires redundant storage protecting against hardware failures, geographic distribution protecting against site disasters, and regular backup verification ensuring recoverability.

Secure disposal when retention periods expire requires cryptographic erasure or physical destruction rather than simple deletion, and documentation proving disposal for compliance audits. Many organizations implement tiered storage strategies with recent logs in high-performance online storage for active monitoring, older logs in lower-cost archival storage for investigation needs, and eventual secure disposal when retention periods expire.

This balances security requirements, operational needs, and cost efficiency.

Cloud Storage Considerations

Organizations using cloud services for log storage must address additional considerations:

  • Data sovereignty requirements may mandate that logs containing specified information remain in Canada or under Canadian legal jurisdiction, limiting choice of cloud regions
  • Shared responsibility models mean cloud providers secure the infrastructure while customers remain responsible for configuring appropriate access controls, encryption, and retention settings
  • Vendor lock-in risks require planning for data portability if changing providers, potentially using open formats or standardized APIs
  • Cost management is essential as cloud storage costs can become substantial with long retention periods and large log volumes—archival storage tiers, compression, and intelligent lifecycle management reduce costs
  • Compliance certification of cloud providers should include verification they hold relevant certifications (ISO 27001, SOC 2) and provide audit evidence of their security practices

Organizations should formally evaluate cloud storage providers against CPCSC requirements before storing security records containing or related to specified information.

Records Management Policies

Organizations need formal policies governing records retention. The policy should include the following elements:

  • Define retention periods for each category of security records with justification based on legal, regulatory, contractual, and operational requirements
  • Specify roles and responsibilities identifying who is responsible for maintaining, protecting, and disposing of each record type
  • Document storage requirements including media types, geographic locations, protection measures, and backup frequencies
  • Establish procedures for secure disposal when retention periods expire, including verification and documentation
  • Define exception processes for litigation holds or regulatory inquiries requiring preservation beyond normal periods
  • Include policy review and update procedures ensuring policies remain current as requirements evolve

The policy should be formally approved by executive management, communicated to relevant personnel, and reviewed during internal audits and external assessments. During Level 2 CPCSC assessments, assessors will examine records retention policies as evidence of mature security program governance.

Practical Implementation Challenges

Organizations face several challenges implementing retention requirements. Storage costs for retaining large volumes of logs and records can be substantial, requiring budget planning and cost-optimization strategies like tiered storage, compression, and selective retention of high-value data.

Technical complexity in implementing automated retention enforcement, secure disposal, and integrity protection requires skilled personnel or external expertise. Legacy systems may lack modern logging capabilities or integration with centralized log management, creating gaps or requiring upgrades.

Balancing retention needs against privacy principles of data minimization can create tension—retaining logs longer improves security but increases privacy risk if logs contain personal information. Organizations should address these challenges through strategic planning, phased implementation starting with highest-risk systems, and investment in appropriate infrastructure and expertise.

The alternative—inadequate retention—creates severe risk by limiting incident investigation capabilities, making compliance demonstration difficult, and potentially violating legal obligations.

Learn More

Additional resources on retention requirements include the following:

Why Choose Plurilock for CPCSC Readiness?

Preparing for CPCSC (Canadian Program for Cyber Security Certification) demands deep knowledge of the certification framework, careful evidence preparation, and hands-on technical implementation. Plurilock delivers with compliance readiness specialists serving Canadian defense suppliers who bring proven experience guiding contractors through cybersecurity certification programs on both sides of the border.

As an established CMMC readiness provider for U.S. defense contractors, we were among the first to extend that expertise north—launching CPCSC readiness services early and serving Canadian defense suppliers from the program's earliest days. We don't conduct audits; we get you ready for them, then help you stay ready.

Why we're the superior choice:

  • First-mover CPCSC expertise: Plurilock was among the first firms to launch dedicated CPCSC readiness services—and among the first to serve clients in this practice—giving your organization a partner with real, accumulated experience preparing suppliers for certification.
  • Deep CMMC heritage: Our established U.S. defense contractor practice has guided organizations through CMMC readiness for years, and those underlying controls map closely to CPCSC—we bring battle-tested methodologies, not theory borrowed from adjacent frameworks.
  • Federal experience on both sides of the border: With extensive engagements across U.S. and Canadian federal government environments, we understand the contractual, technical, and procedural realities that shape defense supply chain compliance.
  • Readiness assessment and gap analysis: We evaluate your current posture against CPCSC requirements, identify control gaps with precision, and deliver clear, prioritized roadmaps that align remediation effort to certification level and contract obligations.
  • Strategy and execution, not just paperwork: Beyond identifying gaps, we help you execute—planning the remediation program, supporting policy and evidence development, and preparing your team and systems so that when the assessor arrives, you're ready.

CPCSC-ready—with proven defense contractor experience guiding every step.

Reach Out Now â†’

+1 (888) 776-9234 (Plurilock)
+1 (310) 530-8260 (Aurora)
+1 (613) 526-4945 (Integra)

sales@plurilock.com

Schedule a free consultation to plot a course toward CPCSC compliance.

loading...

Thank you.

A plurilock representative will contact you within one business day.

Contact Plurilock

+1 (888) 776-9234 (Plurilock)
+1 (310) 530-8260 (Aurora)
+1 (613) 526-4945 (Integra)

sales@plurilock.com

Your information is secure and will only be used to communicate about Plurilock and Plurilock services. We do not sell, rent, or share contact information with third parties. See our Privacy Policy for complete details.

More About Plurilockâ„¢ Services

Subscribe to the newsletter for Plurilock and cybersecurity news, articles, and updates.

You're on the list! Keep an eye out for news from Plurilock.