Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >C2M2
  3. >Situational Awareness
  4. >Situational Awareness - Objective 1
  5. >C2M2-SITUATION-1C
C2M2-SITUATION-1CActive

Logging requirements are established and maintained for IT and OT assets that are important to the delivery of the function and assets within the function that may be leveraged to achieve a threat objective

Statement

Logging requirements are established and maintained for IT and OT assets that are important to the delivery of the function and assets within the function that may be leveraged to achieve a threat objective

Location

Domain
Situational Awareness
Objective
Situational Awareness - Objective 1

Practice Details

Identifier
C2M2-SITUATION-1C
Domain
Situational Awareness
Objective
Objective 1
Maturity Level
MIL-2

Help Text

Define logging requirements for all important IT and OT assets. For example, capturing failed login attempts can point to confidentiality issues, unauthorized changes can indicate integrity issues, and log entries on system down time can reveal availability issues. Requirements for logging may differ for different assets, such as operations technology, field devices, mobile devices, and assets that reside in the cloud. For virtual networks, additional tools or processes may be necessary to enable logging of virtual network traffic. Logs from the cloud, including both cloud infrastructure and cloud assets, should be defined by the organization in the logging requirements as applicable. In addition to the types of events to be logged, organizations should consider what logging requirements may be appropriate such as how logs are to be protected, chain of custody considerations, or retention timelines. Example events that may be logged:

  1. Operating system and application administration events · account creation and deletion · account privilege assignment · configuration changes or software installation
  2. Operating system and application usage events · start up, shut down, and failure of services and applications · network connections and failures · successful and unsuccessful log on attempts · application failures · email and web traffic · systems and files accessed by users
  3. Events occurring on network devices such as · firewalls · switches · routers · wireless access points
  4. Events occurring on OT devices such as · human machine interfaces (HMIs) and operator workstations · protection relays · programmable logic controllers (PLCs) and remote terminal units (RTUs) · smart meters

Related Practices · Input From: Implementing ASSET-1a and ASSET-1b provides input that may be useful for implementing this practice. · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: SITUATION-1a, SITUATION-1b, SITUATION-1c, SITUATION-1d, SITUATION-1f.

AESCSF
AESCSF-SITUATION-1cequivalentvia derived-shared-practice-structure
View in graphReport an issue
← Back to Situational Awareness - Objective 1
Situational Awareness - Objective 16 controls
C2M2-SITUATION-1ALogging is occurring for assets that are important to the delivery of the function, at least in an ad hoc mannerC2M2-SITUATION-1BLogging is occurring for assets within the function that may be leveraged to achieve a threat objective, wherever feasibleC2M2-SITUATION-1CLogging requirements are established and maintained for IT and OT assets that are important to the delivery of the function and assets within the function that may be leveraged to achieve a threat objectiveC2M2-SITUATION-1DLogging requirements are established and maintained for network and host monitoring infrastructure (for example, web gateways, endpoint detection and response software, intrusion detection and prevention systems)C2M2-SITUATION-1ELog data are being aggregated within the functionC2M2-SITUATION-1FMore rigorous logging is performed for higher priority assets