Procedure 17 TECHNICAL
Data Retention & Disposal Policy — how Revique implements this rule today, and how an auditor verifies it.
Policy 17 · PCI DSS Req 3.2, 9.4 · 0 of 4 policy statements fully met · AWS facts collected read-only 2026-08-13
← All 21 procedures
📘← Back to Policy 17 — Data Retention & Disposal PolicyThe rule this procedure implements
How Revique implements this today
Retention is implemented per data type. Production application logs in us-e****-2 are retained for 1827 days (5 years) across 50 log groups, and production us-e****-1 retains 6 groups for 180 days. Database point-in-time recovery is bounded by the RDS backup retention window — 14 days for the production Aurora cluster. Secure disposal of encrypted data is achievable through cryptographic erasure: because production storage is KMS-encrypted, destroying or disabling the key renders the data unreadable without touching the media.
The rule against the current state
Each row takes a statement from Policy 17 and states what is actually configured. Meets = implemented as written. Partial = implemented, but not everywhere or not to the full standard. Gap = not implemented. N/A = not verifiable from infrastructure configuration.
| The rule | Current state | Verdict |
|---|
| Retention periods documented for each data type | Retention is configured per log group and per database but is not documented as a policy table, and a large number of log groups have no retention at all. | Partial |
| Data retained only for the defined business/legal period | Where retention is set it is deliberate (5 years / 180 days / 14 days). Where it is unset, data is retained indefinitely by default. | Gap |
| Secure, irreversible disposal of CHD/PHI when no longer required | Cryptographic erasure is available for KMS-encrypted stores. Unencrypted stores (Procedure 09) cannot be disposed of this way. | Partial |
| Lifecycle management on object storage | S3 lifecycle rules exist on 1 of 22 production buckets, 1 of 17 UAT and 2 of 40 dev. | Gap |
🔍 Auditor verification — where to log in and what you will see
Log retentionConsole → CloudWatch → Log groups, per account and region → the Retention column. Production us-e****-2 shows 1827 days on 50 groups; us-e****-1 shows 180 days on 6.
Log groups with no retentionSame view → sort by Retention → entries showing Never expire: 25 in production us-e****-2, 1 in us-e****-1, 58 in UAT, 92 in dev.
Database retention windowConsole → RDS → production us-e****-1 cluster → Maintenance & backups → Automated backups: 14 days.
S3 lifecycleConsole → S3 → each bucket → Management → Lifecycle rules. Only one production bucket has any.
Cryptographic erasure capabilityConsole → KMS → Customer managed keys → the key protecting a given store; scheduling key deletion is the disposal mechanism.
Team process
The Security Officer defines retention periods per data type; DevOps implements them as log-group retention settings, RDS backup windows and S3 lifecycle rules. Disposal of encrypted data is performed by scheduling deletion of the covering KMS key, which is itself a logged, permission-restricted action.
⚠️ Where reality does not meet the policy
- 176 log groups across the estate have no retention configured (25 production us-e****-2, 1 production us-e****-1, 58 UAT, 92 dev) and therefore retain data indefinitely. The policy requires a defined retention period for each data type and requires that data not be kept beyond it.
- S3 lifecycle management is essentially absent — 1 of 22 production buckets, 1 of 17 UAT and 2 of 40 dev have any lifecycle rule. Objects, including CloudTrail archives, accumulate without a defined expiry.
- No documented retention schedule mapping data type to retention period exists, so what is configured cannot be checked against what was intended.
- Cryptographic erasure is unavailable for the unencrypted stores listed in Procedure 09 (one production legacy MySQL instance, four UAT buckets, two dev volumes).
Evidence location. Retention schedule documentation would be held by the Security Officer; all configured retention is visible in AWS.
📘Back to the PolicyPolicy 17 — Data Retention & Disposal Policy (PCI DSS Req 3.2, 9.4)←