Security wants incident logs kept long enough for investigations yet not retained forever without justification. Which policy approach fits?
Select an answer to reveal the explanation.
Short Explanation
Keep the incident logs long enough to finish the investigation—and not forever just because disk is cheap. A retention policy is the grown-up middle path between shredding everything tomorrow and hoarding forever with no reason.
Full Explanation
Data retention policies define how long assets and records, including investigative logs, must be kept to meet legal, regulatory, and operational needs, and when they should be disposed. Extremely short blanket deletion, indefinite retention without justification, or informal personal USB copies fail that balance. Applying retention rules to municipal incident logs supports Domain 4.2 data retention within asset management.