ED Decision 2023/010/R
When complying with the requirements under points (a)(1)(iv) and (a)(4), the competent authority should establish a data retention policy defining procedures to:
(a) manage relevant information security data files;
(b) establish the periodical assessment of their content; and
(c) define the criteria to allow deletion of records of information security events when the objective of requirement (a)(4) has been met.
Loading collections...