The organization must ensure that logs cover all required system and security events, including system resource usage, service activation or shutdown, and logs from security tools such as antivirus, intrusion detection systems, and firewalls.
Logs must be retained for at least six months and longer if risk analysis shows that extended retention is needed for effective incident management. For entities designated as critical infrastructure, logs must be stored within the territory of Slovenia, with a possible secondary copy located within another EU Member State.