ADORSYS-GIS / ADORSYS-GIS/lightbridge-authz
[Story]: Audit log retention policy (180-day minimum)
- 主要言語
- Rust
- スター
- 0
- フォーク
- 1
- 平均マージ
- 6時間 42分
- マージ済み PR(30日)
- 246
説明
## Summary
Document and implement a configurable audit-log retention policy with a 180-day minimum, matching the enterprise bar set by GitHub's audit log.
## Intent / Source of truth
180-day retention is the named competitive bar; falling short is a concrete, checkable RFP gap. Part of [Epic] SIEM-exportable audit log.
## Scope
- [ ] Retention configuration (minimum 180 days, customer-configurable longer)
- [ ] Storage/lifecycle implementation enforcing the retention window
- [ ] Published retention-policy documentation for customer security reviews
## Out of scope
- Long-term (multi-year) archival tiering (only if a customer specifically requires it later)
## Verification
An event older than the configured retention window is provably no longer queryable/exportable; documentation reviewed against the SOC 2 readiness epic's evidence requirements.
## Risk assessment
Retention that's shorter than advertised is a compliance misrepresentation risk; the enforcement mechanism must be tested, not just documented.
## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.
コントリビューションガイド
評価
この issue はまだ評価されていません。