Skip to main content

CCC.ObjStor.C04: Objects have an Effective Retention Policy by Default

Control ID:CCC.ObjStor.C04
Title:Objects have an Effective Retention Policy by Default
Objective:Ensure that all objects stored in the object storage system have a retention policy applied by default, preventing premature deletion or modification of objects and ensuring compliance with data retention regulations.
Control Family:
Data

Related Threats

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.Core.TH06Data is Lost or CorruptedServices that rely on accurate data are susceptible to disruption in the event of data loss or corruption. Any actions that lead to the unintended deletion, alteration, or limited access to data can impact the availability of the service and the system it is part of.
1
1
0

Related Capabilities

IDTitleDescription
CCC.Core.F11BackupThe service can generate copies of its data or configurations in the form of automated backups, snapshot-based backups, or incremental backups.
CCC.Core.F18Resource VersioningThe service assigns versions to child resources to preserve, retrieve, and restore past iterations.

Guideline Mappings

Reference IDEntry IDStrengthRemarks
NIST-CSF
PR.DS-1
0
-
CCM
DSP-16
0
-
ISO_27001
2022 A.8.1.4
0
-
NIST_800_53
SC-28
0
-
NIST_800_53
CP-10
0
-

Assessment Requirements

IDDescriptionApplicability
CCC.ObjStor.C04.TR01When an object is uploaded to the object storage system, the object MUST automatically receive a default retention policy that prevents premature deletion or modification.
tlp-clear
tlp-green
tlp-amber
tlp-red
CCC.ObjStor.C04.TR02When an attempt is made to delete or modify an object that is subject to an active retention policy, the service MUST prevent the action from being completed.
tlp-clear
tlp-green
tlp-amber
tlp-red