nerc-project / operations

Issues related to the operation of the NERC OpenShift environment
1 stars 0 forks source link

Exploration of Additional Personas for Observability Cluster Based on Retention Rate Requirements #461

Open schwesig opened 3 months ago

schwesig commented 3 months ago

Background

In recent discussions regarding the observability cluster, it has become apparent that our current persona coverage may not fully address all needs, particularly in terms of metrics retention rates. Two key additional personas have been identified as essential to ensuring our observability infrastructure meets all operational and compliance requirements:

  1. IRS (Internal Revenue Service) Compliance Persona: This persona focuses on the requirements for storing data necessary to back up invoices and support or facilitate financial audits. Understanding the specifics of data retention for this persona is crucial for compliance with tax laws and regulations.
  2. Security Persona: For this persona, the primary concern is the retention of data necessary to investigate security incidents. A minimum retention period of 90+ days has been suggested, but further investigation is required to define the exact requirements.

Goals

Identify Specific Data Retention Requirements for IRS Compliance Persona: Determine the types of data that need to be retained, the duration of retention, and any specific formats or standards that must be adhered to.

Define Data Retention Needs for Security Persona: Establish the minimum data retention period necessary to support effective security incident investigations. This involves identifying the types of data crucial for such investigations and any relevant standards or best practices.

Tasks

Discussion Points:

schwesig commented 3 weeks ago
schwesig commented 3 weeks ago