Determines what the organisation will be able to reconstruct after the fact, and how long it keeps the ability to do so.
Authentication, authorisation changes, privileged actions, data access at defined classifications, and configuration change. List the classes, not the systems, so new systems inherit the requirement.
Searchable retention and archival retention are different numbers and different costs. State both. Intrusions are frequently discovered months after they begin, and a thirty day window will not reach back to the start.
Logs must be written where the account that generated the event cannot alter them. A privileged user who can edit the record of their own actions makes the whole exercise decorative.
One authoritative time source, stated. Correlating across systems whose clocks disagree is the quiet reason timelines cannot be built.
Collection is not detection. Name the conditions that generate an alert, who receives it, and the expected response time.
Credentials, card data, health information and full personal records. Logs are widely readable, and this clause prevents the logging system becoming the largest uncontrolled copy of sensitive data in the estate.