CSP Compliance with Applicable Records Retention Policies, v1.0

Credential Service Providers (CSPs) must comply with records retention policies as appropriate for the organization, including adhering to applicable laws, regulations, and policies. CSPs must also inform their subscribers of their records retention policy.

Assessment Steps (2)

1
Retention Policy Compliance (RetentionPolicyCompliance)
Does the CSP comply with retention policies as required by applicable laws?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that support whether the CSP has appropriate records retention policies.
2
Retention Policy Informing (RetentionPolicyInforming)
Does the CSP inform their subscribers of their retention policy?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that support whether the CSP informs subscribers of its record retention policies.

Conformance Criteria (1)

C1
The CSP shall comply with its respective records retention policies in accordance with applicable laws, regulations, and policies, including any National Archives and Records Administration (NARA) records retention schedules that may apply. If the CSP opts to retain records in the absence of any mandatory requirements, the CSP SHALL conduct a risk management process, including assessments of privacy and security risks, to determine how long records should be retained and SHALL inform the subscriber of that retention policy.
Citation
NIST SP 800-63B
Sections 4.1.5, 4.2.5, and 4.3.5