Skip to main content

CCC.Logging.TH05: Log Retention Policy Evasion or Misconfiguration

Threat ID:CCC.Logging.TH05
Title:Log Retention Policy Evasion or Misconfiguration
Description:

Log data is deleted prematurely or retained longer than legally required due to misconfigured retention policies, manual overrides, or evasion tactics. This can lead to non-compliance with regulatory requirements or loss of critical forensic evidence.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1070.004
0
Indicator Removal on Host: File Deletion
MITRE-ATT&CK
T1485
0
Data Destruction
MITRE-ATT&CK
T1562.008
0
Impair Defenses: Disable Cloud Logs

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.Logging.C02Enforce Data Retention Policy for LogsEnsure that the retention period configured for logs aligns with the organization's data retention policy. Data
1
2
2