What the buyer is really asking
How long are security logs kept, and would they still exist if you discovered an incident months later? One year is a common expectation, and some frameworks require longer.
Other ways buyers ask it
Every one of these wants the same answer:
- “How long do you retain security logs?”
- “Do you retain audit logs for at least one year?”
- “Are logs protected from tampering?”
Evidence to have ready
- Log retention settings for each log source
- Access controls on log storage
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.