Misconfigured Logging Retention
Overview
Misconfigured logging retention occurs when an organization improperly sets the duration for which log data is stored, either retaining logs for too short or excessively long periods. This misconfiguration can result from unclear policies, lack of oversight, or technical errors in log management systems.
Why It Matters
- Security impact: Insufficient retention periods may prevent detection and investigation of security incidents, while excessive retention increases exposure of sensitive data.
- Business risk: Non-compliance with regulatory requirements regarding data retention can lead to legal penalties and reputational damage.
- Common consequences: Loss of forensic evidence, increased risk of data breaches, and difficulties in auditing and incident response.
Where It Appears
- Environments: Cloud services, on-premises data centers, and hybrid infrastructures.
- Systems or processes: Security information and event management (SIEM), application logs, system logs, and audit trails.
- Typical conditions: Lack of defined retention policies, inadequate monitoring of log storage, or default system settings left unchanged.
How It Is Exploited (High Level)
Attackers exploit misconfigured logging retention by leveraging the absence of adequate logs to cover their activities, hindering detection and investigation. Excessive retention may also expose sensitive information if logs are accessed by unauthorized parties.
How It Is Addressed (High Level)
Addressing this issue involves establishing clear logging retention policies aligned with legal and operational requirements, implementing access controls to protect log data, and regularly reviewing retention settings to ensure compliance and effectiveness.
Related Topics
Log management, data retention policies, audit trails, security information and event management (SIEM), compliance, incident response, data privacy.