Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >AESCSF
  3. >SITUATION
  4. >Perform Logging
  5. >AESCSF-SITUATION-1c
AESCSF-SITUATION-1cActive

Logging requirements are established and maintained for IT and OT assets that are important to the delivery of the fu...

Statement

Logging requirements are established and maintained for IT and OT assets that are important to the delivery of the function and assets within the function that may be leveraged to achieve a threat objective

Context and Guidance: Define logging requirements for all important IT and OT assets. For example, capturing failed login attempts can point to confidentiality issues, unauthorised changes can indicate integrity issues, and log entries on system down time can reveal availability issues. Requirements for logging may differ for different assets, such as operations technology, field devices, mobile devices, and assets that reside in the cloud. For virtual networks, additional tools or processes may be necessary to enable logging of virtual network traffic. Logs from the cloud, including both cloud infrastructure and cloud assets, should be defined by the organisation in the logging requirements as applicable. In addition to the types of events to be logged, organisations should consider what logging requirements may be appropriate such as how logs are to be protected, chain of custody considerations, or retention timelines. Example events that may be logged:

  1. Operating system and application administration events • account creation and deletion • account privilege assignment • configuration changes or software installation
  2. Operating system and application usage events • start up, shut down, and failure of services and applications • network connections and failures • successful and unsuccessful log on attempts • application failures • email and web traffic • systems and files accessed by users
  3. Events occurring on network devices such as • firewalls • switches • routers • wireless access points
  4. Events occurring on OT devices such as • human machine interfaces (HMIs) and operator workstations • protection relays • programmable logic controllers (PLCs) and remote terminal units (RTUs) • smart meters

Related Practices • Input From: Implementing ASSET-1a and ASSET-1b provides input that may be useful for implementing this practice. • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: SITUATION-1a, SITUATION-1b, SITUATION-1c, SITUATION-1d, SITUATION-1f.

Location

Domain
SITUATION
Objective
Perform Logging

Practice Details

Identifier
AESCSF-SITUATION-1c
Type
Practice
Domain
SITUATION
Objective
Perform Logging

Maturity Level

MIL-1MIL-2MIL-3

Security Profile

SP-1SP-2SP-3
ISM
ISM-0580relatedvia aescsf-reference
ISM-0585relatedvia aescsf-reference
ISM-1405relatedvia aescsf-reference
C2M2
C2M2-SITUATION-1Cequivalentvia derived-shared-practice-structure
ISO 27001
ISO27001-8.15relatedvia aescsf-reference
View in graphReport an issue
← Back to Perform Logging
Perform Logging6 controls
AESCSF-SITUATION-1aLogging is occurring for assets that are important to the delivery of the function, at least in an ad hoc mannerAESCSF-SITUATION-1bLogging is occurring for assets within the function that may be leveraged to achieve a threat objective, wherever fea...AESCSF-SITUATION-1cLogging requirements are established and maintained for IT and OT assets that are important to the delivery of the fu...AESCSF-SITUATION-1dLogging requirements are established and maintained for network and host monitoring infrastructure (for example, web ...AESCSF-SITUATION-1eLog data are being aggregated within the functionAESCSF-SITUATION-1fMore rigorous logging is performed for higher priority assets