The company formally defines how long logs must be retained and how they must be protected from tampering
Sekit's Log protection and retention policy, one of the topic-specific policies A.5.1 expects, defines how long each log category is kept and what protects it from tampering, even by an attacker with admin rights.
Defining in writing how long logs are kept and what protects them from tampering is the policy precondition for A.8.15's protection and retention requirement.