Skip to content

Narrow MI-22 to SDLC-specific evidence retention - #104

Open
germanptr wants to merge 2 commits into
finos-labs:mainfrom
trigosec:narrow-mi-22-to-sdlc-scope
Open

germanptr wants to merge 2 commits into
finos-labs:mainfrom
trigosec:narrow-mi-22-to-sdlc-scope

Conversation

@germanptr

Copy link
Copy Markdown
Contributor

Scopes the control to the audit/compliance evidence SDLC controls produce (review outcomes, test evidence, approvals, build artefacts, audit logs) rather than general enterprise data retention.
Requirements trimmed from 10 to 6 bullets; disposal mechanics (sanitisation, legal holds, disposal logging) are deferred to the organisation's general data retention policy instead of being re-specified here.

Scopes the control to the audit/compliance evidence SDLC controls
produce (review outcomes, test evidence, approvals, build artefacts,
audit logs) rather than general enterprise data retention. Requirements
trimmed from 10 to 6 bullets; disposal mechanics (sanitisation, legal
holds, disposal logging) are deferred to the organisation's general
data retention policy instead of being re-specified here.

Signed-off-by: Germán Fuentes Capella <47056480+germanptr@users.noreply.github.com>
* The organisation MUST classify SDLC-generated governance record and artefact types (such as review outcomes, test evidence, scan results, approval records, deployment records, build artefacts, audit logs, and exception records) and assign each class a minimum retention period
* The minimum retention period for a record class MUST NOT be less than the longest applicable regulatory, contractual, or audit cycle requirement for that class
* Records MUST be immutable and tamper-evident for the duration of their minimum retention period; they MUST NOT be modifiable, deletable, or replaceable outside an approved and auditable exception process
* Retention MUST extend to SDLC records held in third-party or SaaS tooling (such as CI/CD, ticketing, code review, and artefact repositories), through contractual terms, configuration, or export before offboarding

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

in accordance to requirement 1

…ent 1

Clarify that the third-party/SaaS retention requirement covers the
record classes and minimum periods already established by the
classification requirement, rather than reading as a separate,
unscoped obligation.

Signed-off-by: Germán Fuentes Capella <47056480+germanptr@users.noreply.github.com>
@germanptr
germanptr force-pushed the narrow-mi-22-to-sdlc-scope branch from eba743b to c775575 Compare September 14, 2026 14:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant