LOG-001: Audit Log Retention Settings

Platform
Google Workspace
Category
Logging, Alerting & Monitoring
Severity
High
Zero Trust pillar
Visibility & Analytics (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Audit logs should be retained for an adequate period to support incident investigation and compliance requirements. Default retention varies by Workspace edition

Recommended value

Audit log retention of 12 months or longer; extended via BigQuery export for long-term retention

Remediation

Admin Console > Reporting > Audit and investigation > Review log availability. Configure BigQuery export via Admin Console > Reporting > BigQuery export for long-term retention

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for LOG-001
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
AU-11, AU-4
CIS Benchmark
7.1
MITRE ATT&CK
T1070, T1562.008