Log data are being aggregated within the function
Context and Guidance: Collect log data from different assets and aggregate it in a central repository. Aggregation may be performed within the function or elsewhere in the enterprise depending on several considerations such as enterprise architecture and regulatory requirements. The repository may be a simple log server, or log management infrastructure that includes centralised log servers and log data storage, or a vendor-supported security information and event management (SIEM) system. Doing so makes log data available even when individual assets are offline or destroyed. Aggregation can be especially beneficial for gathering information from operations technology assets with a limited ability to log locally. Additionally, by aggregating log data from various assets, the organisation can correlate data to identify patterns and anomalies.