ED Decision 2023/009/R
When complying with the requirements under points (a)(1)(vi) and (a)(5), the organisation should establish a data retention policy defining procedures to:
(a) manage relevant security data files;
(b) establish the periodical assessment of their content; and
(c) define the criteria to allow deletion of records of information security events when the objective of the requirement under (a)(5) has been met.
Loading collections...