Log Retention Guidelines
- Home
- Offices and Services
- Technology & Innovation
- IT Guidelines & Policies
- Log Retention Guidelines
- AP Summer Institute
- Deliberative Citizenship Initiative
- Division of Student Life
- Institutional Biosafety Committee
- Jay Hurt Hub for Innovation and Entrepreneurship
- The College Crisis Initiative
- The Office of Equity Compliance
- Archives and Special Collections
- College Communications
- College Store
- Arts & Creative Engagement
- Academic Access & Disability Resources
- Academic Affairs
- Lula Bell's Resource Center
- Animal Care and Use
- Auxiliary Services
- Controller's Office
- Post and Print
- Carnegie Guest House
- Human Subjects IRB
- CatCard Services
- Matthews Center for Career Development
- Center for Teaching and Learning
- Chidsey Program for Leadership Development
- Civic Engagement
- College Relations
- Davidson Outdoors
- Dean Rusk International Studies Program
- Dining Services
- Center for Student Diversity and Inclusion
- Education Abroad
-
Environmental Health and Safety
- Fire & Life Safety
-
Occupational Safety
- Contractor Safety
- Confined Space Entry Program
- Electrical Safety
- Lockout Tagout Procedure
- Ladders and Scaffolding
- Personal Protective Equipment
- Respiratory Protection
- Hearing Conservation Program
- Hand and Power Tools
- Steam System Safety
- Welding, Cutting and Brazing
- Compressed Gas Cylinders
- Construction and Excavation
- Fork Lift Safety
- Motor Vehicle Safety
- Golf Cart Safety
- Biological, Chemical & Laboratory Safety
- Chemical Inventory
- Safety Data Sheets
- Training
- Environmental
- Indoor Air Quality
- Ergonomics
- Forms and Policies
- Incident Reporting
- EHS Committee
-
Office of Fellowships
- Appointments & Contact Information
-
Fellowship Opportunities
- Beinecke Scholarship
- Boren Fellowships
- Churchill Scholarship
- Critical Language Scholarship Program
- DAAD Rise Germany
- Fulbright U.S. Student Program
- Gaither Junior Fellows Program
- Gates Cambridge Scholarships
- Goldwater Scholarships
- Knight-Hennessy Scholars
- Luce Scholarships
- Marshall Scholarships
- McCall MacBain Scholarships
- National Science Foundation Graduate Fellowships
- NOAA Hollings Scholarship
- Paul & Daisy Soros Fellowships for New Americans
- Pickering Fellowship Program
- Rangel Fellowship Program
- Rhodes Scholarships
- Schwarzman Scholars
- Smith Scholarship
- Truman Scholarships
- Udall Scholarships
- UK Summer Institutes
- Watson Fellowship
- Fellowship Resources for Faculty & Staff
- Finance & Administration
-
Office of Sponsored Programs
- Research Compliance
- Proposal Development
-
Policies
- NSF and NIH Sexual Harassment Notification Policy
- NSF and NIH Breach of Personally Identifiable Information (PII) Policy
- Conflict of Interest
- NIH and NSF Public Access Policy
- Policy and Procedure for Responsible Conduct of Research
- Effort Reporting Policy
- Export Control Policy
- Ethical Conduct in Research and Scholarship
- Financial Conflict of Interest Policy
- Full Year Sabbatical Fringe Benefits
- Grants Record Management Policy
- Drug Free Workplace
- Intellectual Property Policy
- Indirect Cost
- Postdoctoral Positions Policy
- Determination of Allowable Costs Policy
- Summer Salary Distribution
-
Post Award Management
- Procurement Policy
- Suspension and Debarment Policy and Procedure
- Grant-Related Expenditure Approval and Monitoring Procedure
- Unallowable Cost Policy
- Cost Transfer Policy
- Sub-Recipient Monitoring Policy
- Award Cash Management Service Procedure
- Hiring New Personnel
- Rebudgeting and Program Revisions
- Reporting and Closeout
- Staff
- Guest Services
- Student Health and Well-Being
- Housing and Relocation
-
Human Resources
- Benefits
- Retirement
-
Employee Guide
- Americans with Disabilities (ADA)
- Leave Accruals
- Attendance
- Background Checking Policy
- Confidentiality of Information
- Conflict of Interest
- Consensual Relationships
- Copyrights
- Dependent Tuition Assistance Policy
- Disciplinary Action
- Dress Code
- Drug-free Workplace
- Employee Designations
- Employee Files
- Employee Honor Code
- Employment and Recruitment
- Employment of Minors
- Employment of Relatives
- Family Medical Leave Act
- Firearms and Dangerous Weapons
- Funeral and Bereavement Leave
- Grievance Procedure
- Identification Cards/CatCards
- Immigration Sponsorship for College Employees
- Inclement Weather
- Jury Duty
- Long Term Disability
- Military Leave
- Non-Discrimination Policies
- Occupational Health and Safety
- Other Employment
- Overtime
- Parental Leave
- Pay During Special Circumstances
- Pet Policy
- Political Activity
- Reduced Hours and Voluntary Time Off
- References for Former Employees
- Relocation and Moving Expense Policy
- Resignation
- Retirement Health Insurance
- Short Term Disability
- Sick Leave
- Smoking Policy
- Sports Betting Policy
- Staff Tuition Policy
- Support for Lactation Policy
- Remote Work Policy
- Transfer, Promotion and Classification
- Use of College-owned Equipment and Work Areas
- Vacation
- Vehicles/Parking
- Volunteer Policy
- Voting
- Work Schedules
- Workers Compensation
- Employee Resources
- Manager Resources
- Work at Davidson
- Student Employment
- HR Staff
- Institutional Effectiveness
- International Student Engagement
- Investment Office
- July Experience
- Laundry Self-Service Facilities
- Motor Pool Services
- Physical Plant
- Public Safety
-
Registrar
- Academic Calendars
- Course Offerings
- Course Registration and WebTree Overview
- Holistic Advising
- Student Schedules, Grades, Add/Drop
- Transcripts
- Record Requests & Forms
- Graduation Requirements
- Transfer Credit
- New Student Resources
- Faculty Resources
- College Catalog
- Academic Regulations
- FERPA
- Graduating Class Profiles
- Staff
- Religious and Spiritual Life
- Residence Life
- Staff Council
-
Student Activities
-
Student Organizations
- Academic Clubs and Societies
- Affinity & Identity Organizations
- Civic Engagement Council
- Fraternity & Sorority Life (Patterson Court Council)
- Health & Wellness Organizations
- Media Organizations
- Performance Groups
- Political Organizations
- Pre-Professional Organizations
- Religious Organizations
- Special Interest and Recreational Organizations
- Programs
- Student Activities Staff
-
Student Organizations
- Sustainability Office
-
Technology & Innovation
- Getting Started
- Services
-
IT Guidelines & Policies
- Emeriti Technology Policy
- Davidson College Technology Terms of Service
- Account Management
- College Access to Electronic Communications Policy
- Computer Workstation Purchasing
- Copyright Compliance with Laws and Acts
- Data Privacy Statement
- Data Security Policy
- Desktop Computer Support
- Guidelines for Mass Email Communications
- Information Security Plan
- Information Systems Security Policy
- Log Retention Guidelines
- Moodle Usage Tracking
- Purchasing Technology
- About
- Staff
- The Farm at Davidson
- Wildcat Wellness
Log Retention Guidelines
This document exists to guide Davidson College Technology & Innovation (“T&I”) staff and others who administer information technology (“IT”) systems for Davidson regarding the minimum and maximum retention standards for system log files.
A log file or “log” is the generic term for any information technology based event or activity record, including but not limited to, access, network, and/or security information involving status, successes, failures, and activity.
Logs: Categories and Purposes
For the purposes of these guidelines, logs are categorized into four types with the recognition that categorizing a set of records into a single type of log may be difficult as some logs have more than one purpose.
- Access Logs: Records regarding authentication or authorization to an information technology resource, along with physical access control logs. These include records of successful and unsuccessful attempts to access college technology systems and services and metadata about these attempts.
- System Logs: Records pertaining to the operation, use and health of a system, application or other IT element. Examples of system logs include application (web, ERP, application, cloud service), database, or system (syslog, event) logs, as well as remote access logs, or other records of user activity after authentication to a system.
- Network Logs: Records pertaining to network communications, including the establishment, association, or resolution, of a connection between two communicating technology devices. Examples of network logs include DHCP lease logs, NPS logs, DNS query logs, network flow data, address translation (NAT/PAT) logs, router/switch logs, telephony/telecommunications records (including call detail records), wireless controller logs, and SMTP logs.
- Security Logs: Records that pertain to possible or actual policy violations, computer intrusions, malicious activity, misuse of resources, illegal or unsanctioned activity, privacy violations, and all other security records. Examples of security logs would include anti-virus/endpoint protection service logs, intrusion detection/prevention system records, incident records, and packet captures.
Logging systems are designed to capture metadata around the use of services. Davidson logging systems should not, to the maximum extent possible, capture the content of encrypted application communications (such as the content of emails, files, voicemail messages or other documents), and all such requests for those data should be made in accordance with the College Access to Electronic Communications Policy.
However, metadata captured in logs may include the IP or other network address a student, employee or visitor is using when accessing external websites, including: geolocation; the URL or resource name of websites accessed; email recipients, subject lines and other communications metadata; location information and other identifying material. Individuals using Davidson systems should be aware that their use of such IT services and systems is monitored in accordance with Davidson policy.
Recommended Log Retention Periods
“Minimum Period of Readily Accessible Logging” is defined as the time period for which records are available for immediate review in Davidson’s logging systems to support IT system administration, security investigations, authorized external requests and other accesses. Readily accessible means that the record should be available for on-demand, real-time search and retrieval by T&I staff.
“Maximum Period of Archival Logging (Overall Retention Period)” defines the maximum time that log files should be maintained. Log files, including backup copies, should not be retained after these time periods. Note: while Davidson works to maintain the maximum retention period, the possibility exists that, due to previously undiscovered logs or records or developing or future forensic technologies, logs records archived or purged may be recoverable.
|
Type of Log |
Minimum Period of Readily Accessible Logging
From the time the record was generated |
Maximum Period of Archival Logging (Overall Retention Period)
From the time the record was generated |
|
Access Logs |
180 days |
365 days |
|
System Logs |
60 days |
365 days |
|
Network Logs |
60 days |
365 days |
|
Security Logs |
Automated alerting of possible security events by security systems: 90 days
Staff-created records of security events and incidents: 365 days |
Automated alerting of possible security events by security systems: 365 days
Staff-created records of security events and incidents: 1 year (events not leading to incidents) 5 years or indefinite (incidents, law enforcement or legal requests, etc.) |
Recommended Log Retention Periods for Vendor-Hosted Systems
In circumstances where Davidson contracts the operation of IT services to third parties (such as in the use of software as a service or SaaS solutions), T&I staff should inquire as to the logging practices of vendors during the initial contracting phase to understand any variance between Davidson guidelines and vendor practices.
For services where Davidson can configure log retention within a system, authorized Davidson T&I staff should work to mirror these guidelines to the extent possible.
Access to Log Files
Authorized Davidson staff may routinely access and use log files in accordance with their professional responsibilities, in line with the uses anticipated by the College Access to Electronic Communications Policy.
All requests from Davidson students, faculty and staff for log file access or information should follow the process documented in the College Access to Electronic Communications policy.
All requests from third parties, including requests from law enforcement agencies or legal subpoenas, must be reviewed by the Vice President and General Counsel to obtain authorization to proceed.
Last revised April 7, 2022