For how long must physical access logs be retained?

Prepare for the NERC CIP v7 Standards Test with our comprehensive quiz. Utilize flashcards, multiple-choice questions, hints, and explanations. Master every concept to ace your exam!

The requirement to retain physical access logs for 90 days is grounded in the CIP standards to maintain an adequate level of security and oversight over critical infrastructure. By retaining these logs for this duration, organizations can effectively monitor and audit physical access to their facilities, which is crucial for both incident response and compliance verification. This timeframe allows for a sufficient window to conduct investigations if needed and ensures that any anomalies in access patterns can be scrutinized within a reasonable period.

Longer retention periods might lead to unnecessary storage costs or complicate data management, while shorter retention might not provide enough historical data for effective analysis. Therefore, 90 days strikes a balance between operational efficiency and security needs.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy