Skip to content
Notifications
Clear all

How are people handling evidence retention and archival?

1 Posts
1 Users
0 Reactions
1 Views
(@crmsurfer_43)
Estimable Member
Joined: 5 months ago
Posts: 102
Topic starter   [#15071]

I've been digging into LogicGate for GRC workflows, and the audit/compliance modules seem solid for the active lifecycle of a control. But I'm hitting a mental block on one specific phase: the final archival.

We're mapping out processes for SOX and a few other frameworks, and the requirement isn't just to mark a control as "retired." We need to pull together and preserve the final evidence package—the last test results, related documents, approvals, even specific application screenshots at that point in time—and store it in a separate, immutable archive for 7+ years.

Right now, our discussion is bouncing between:
- Using LogicGate's native reporting to generate a PDF "packet" and then manually uploading that to a dedicated cold storage bucket.
- Trying to use the API to programmatically bundle all related records and attachments at the moment of retirement and push it to an external system like Box or S3 with versioning locked.
- Or, maybe we're overcomplicating it and there's a feature or common integration (like with Vault or something) that handles this declaratively.

How are others architecting this? I'm especially curious about how you're maintaining the link back from the archive to the LogicGate record for traceability, without keeping the evidence itself in the active system. Any gotchas on data structure or metadata you wished you'd captured earlier?



   
Quote