Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >AESCSF
  3. >SITUATION
  4. >SITUATION Anti-Patterns
  5. >AESCSF-SITUATION-AP10
AESCSF-SITUATION-AP10Active

Logging data from impacted assets cannot be inspected when investigating a cybersecurity event

Statement

Logging data from impacted assets cannot be inspected when investigating a cybersecurity event

Context and Guidance: Logging data that is collected from your assets (such as networks, systems, and applications) can serve as a key source of information to support the early detection of a cybersecurity threat.

Ensuring that logging data is available when investigating a cybersecurity event is also important. When assets are impacted, and logging data generated by those assets is unavailable, you have a limited ability to respond.

Example activities that indicate this Anti-Pattern is Present include:

  • Logging data is stored in a cloud (Internet) based repository, and logging data in this repository cannot be inspected during a Distributed Denial of Service (DDOS) attack, or;
  • Logging data cannot be centrally inspected by your security monitoring solution as it is stored in a segregated network inaccessible during an incident, or;
  • Logging data cannot be inspected given security logging requirements were not established by the function, and therefore the logging data is not fit-for-purpose or is unintelligible.

Location

Domain
SITUATION
Objective
SITUATION Anti-Patterns

Practice Details

Identifier
AESCSF-SITUATION-AP10
Type
Anti-pattern
Domain
SITUATION
Objective
SITUATION Anti-Patterns

Maturity Level

MIL-1MIL-2MIL-3

Security Profile

SP-1SP-2SP-3
ISM
ISM-1405relatedvia aescsf-reference
ISM-0120relatedvia aescsf-reference
View in graphReport an issue
← Back to SITUATION Anti-Patterns
SITUATION Anti-Patterns11 controls
AESCSF-SITUATION-AP1Operational assets are monitored only for performance and not for cybersecurity eventsAESCSF-SITUATION-AP2Logging data is only monitored when a cybersecurity incident occursAESCSF-SITUATION-AP3Normal asset operation is not sufficiently baselined to support the identification of abnormal asset operationAESCSF-SITUATION-AP4Alerts and alarms are not configured to include security eventsAESCSF-SITUATION-AP5Logging data is not time synchronisedAESCSF-SITUATION-AP6Logging data from critical assets is only stored on the asset and not centralisedAESCSF-SITUATION-AP7Identities (users) have edit (write) access to centralised logging data without a confirmed needAESCSF-SITUATION-AP8Third party vendors or services have privileged access that is not loggedAESCSF-SITUATION-AP9Indicators of Compromise (IOCs) are only monitored and considered during or after a cybersecurity incidentAESCSF-SITUATION-AP10Logging data from impacted assets cannot be inspected when investigating a cybersecurity eventAESCSF-SITUATION-AP11Indicators of Compromise cannot be added to security monitoring solutions that monitor critical assets