ADORSYS-GIS / ADORSYS-GIS/lightbridge-authz

[Story]: Audit log retention policy (180-day minimum)

オープン
#260 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
user-story
主要言語
Rust
スター
0
フォーク
1
平均マージ
6時間 42分
マージ済み PR(30日)
246

説明

## Summary
Document and implement a configurable audit-log retention policy with a 180-day minimum, matching the enterprise bar set by GitHub's audit log.

## Intent / Source of truth
180-day retention is the named competitive bar; falling short is a concrete, checkable RFP gap. Part of [Epic] SIEM-exportable audit log.

## Scope
- [ ] Retention configuration (minimum 180 days, customer-configurable longer)
- [ ] Storage/lifecycle implementation enforcing the retention window
- [ ] Published retention-policy documentation for customer security reviews

## Out of scope
- Long-term (multi-year) archival tiering (only if a customer specifically requires it later)

## Verification
An event older than the configured retention window is provably no longer queryable/exportable; documentation reviewed against the SOC 2 readiness epic's evidence requirements.

## Risk assessment
Retention that's shorter than advertised is a compliance misrepresentation risk; the enforcement mechanism must be tested, not just documented.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。