Discussion
- AuthorPosts
- 8th August 2026 at 9:31 am #3337
Keeping everything forever increases risk, but deleting records too early can break legal, operational, or audit obligations. What should the software requirements state?
8th August 2026 at 9:31 am #3338Accepted editorial answerMap each data type to its owner, purpose, governing retention rule, storage locations, backups, holds, and approved deletion method. State when the clock starts and which event pauses or restarts it.
Require the system to operationalize the policy in practice. The team should be able to find covered records, apply holds, delete or sanitize data across active and backup environments, restrict who can take action, and obtain evidence that the action is complete.
NIST SP 800-53 Revision 5.1 covers retention, media sanitization, backups, authorization, and evidence of control operation. The exact periods still come from the buyer’s records, privacy, legal, and business requirements.
- AuthorPosts
- You must be logged in to reply to this topic.