Procedure 17  TECHNICAL

Data Retention & Disposal Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 17  ·  PCI DSS Req 3.2, 9.4  ·  0 of 4 policy statements fully met  ·  AWS facts collected read-only 2026-08-13
← All 21 procedures 📘← Back to Policy 17 — Data Retention & Disposal PolicyThe rule this procedure implements

How Revique implements this today

Retention is implemented per data type. Production application logs in us-e****-2 are retained for 1827 days (5 years) across 50 log groups, and production us-e****-1 retains 6 groups for 180 days. Database point-in-time recovery is bounded by the RDS backup retention window — 14 days for the production Aurora cluster. Secure disposal of encrypted data is achievable through cryptographic erasure: because production storage is KMS-encrypted, destroying or disabling the key renders the data unreadable without touching the media.

The rule against the current state

Each row takes a statement from Policy 17 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.

The ruleCurrent stateVerdict
Retention periods documented for each data typeRetention is configured per log group and per database but is not documented as a policy table, and a large number of log groups have no retention at all.Partial
Data retained only for the defined business/legal periodWhere retention is set it is deliberate (5 years / 180 days / 14 days). Where it is unset, data is retained indefinitely by default.Gap
Secure, irreversible disposal of CHD/PHI when no longer requiredCryptographic erasure is available for KMS-encrypted stores. Unencrypted stores (Procedure 09) cannot be disposed of this way.Partial
Lifecycle management on object storageS3 lifecycle rules exist on 1 of 22 production buckets, 1 of 17 UAT and 2 of 40 dev.Gap

🔍 Auditor verification — where to log in and what you will see

Log retentionConsole → CloudWatch → Log groups, per account and region → the Retention column. Production us-e****-2 shows 1827 days on 50 groups; us-e****-1 shows 180 days on 6.
Log groups with no retentionSame view → sort by Retention → entries showing Never expire: 25 in production us-e****-2, 1 in us-e****-1, 58 in UAT, 92 in dev.
Database retention windowConsole → RDS → production us-e****-1 cluster → Maintenance & backups → Automated backups: 14 days.
S3 lifecycleConsole → S3 → each bucket → Management → Lifecycle rules. Only one production bucket has any.
Cryptographic erasure capabilityConsole → KMS → Customer managed keys → the key protecting a given store; scheduling key deletion is the disposal mechanism.

Team process

The Security Officer defines retention periods per data type; DevOps implements them as log-group retention settings, RDS backup windows and S3 lifecycle rules. Disposal of encrypted data is performed by scheduling deletion of the covering KMS key, which is itself a logged, permission-restricted action.

⚠️ Where reality does not meet the policy

Evidence location. Retention schedule documentation would be held by the Security Officer; all configured retention is visible in AWS.
📘Back to the PolicyPolicy 17 — Data Retention & Disposal Policy (PCI DSS Req 3.2, 9.4)←
Revique security documentation  ·  generated 2026-08-13  ·  all identifiers masked  ·  AWS facts collected read-only on 2026-08-13
Policies define the rule; procedures describe the implementation and how to verify it.