Skip to main content
MuonPartners
Services
Architecture

Solution design and technology roadmapping

Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security

Security assessments, IAM, and compliance

AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform

Network architecture and cloud platforms

Network DesignCloud StrategyModernisation
Enterprise Architecture

Business-technology alignment

Business AlignmentPortfolio AnalysisGovernance
View all services
ProjectsCase StudiesInsightsToolsAbout
Contact Us

Services

Architecture
Solution AssessmentTechnology RoadmapsIntegration DesignSolution ArchitectureTechnical Design
Cyber Security
AssessmentsIAMComplianceSecurity BaselineCyber Innovation
Network and Platform
Network DesignCloud StrategyModernisation
Enterprise Architecture
Business AlignmentPortfolio AnalysisGovernance
ProjectsCase StudiesInsightsToolsAboutContact
Get in Touch
MuonPartners

Strategic technology consulting for Australian organisations navigating complexity.

Services

  • Architecture
  • Cyber Security
  • Network and Platform
  • Enterprise Architecture

Company

  • About
  • Products
  • Frameworks
  • Cross-Framework Mapping
  • Projects
  • Case Studies
  • Insights
  • Contact

Contact

  • [email protected]
  • Australia
  • LinkedIn

© 2026 Muon Partners. All rights reserved.

ABN 50 669 022 315 · A Muon Group company.

Privacy PolicyTerms of Service
  1. Frameworks
  2. >C2M2
  3. >Situational Awareness
  4. >Situational Awareness - Objective 1
  5. >C2M2-SITUATION-1E
C2M2-SITUATION-1EActive

Log data are being aggregated within the function

Statement

Log data are being aggregated within the function

Location

Domain
Situational Awareness
Objective
Situational Awareness - Objective 1

Practice Details

Identifier
C2M2-SITUATION-1E
Domain
Situational Awareness
Objective
Objective 1
Maturity Level
MIL-2

Help Text

Collect log data from different assets and aggregate it in a central repository. Aggregation may be performed within the function or elsewhere in the enterprise depending on several considerations such as enterprise architecture and regulatory requirements. The repository may be a simple log server, or log management infrastructure that includes centralized log servers and log data storage, or a vendor-supported security information and event management (SIEM) system. Doing so makes log data available even when individual assets are offline or destroyed. Aggregation can be especially beneficial for gathering information from operations technology assets with a limited ability to log locally. Additionally, by aggregating log data from various assets, the organization can correlate data to identify patterns and anomalies.

AESCSF
AESCSF-SITUATION-1eequivalentvia derived-shared-practice-structure
View in graphReport an issue
← Back to Situational Awareness - Objective 1
Situational Awareness - Objective 16 controls
C2M2-SITUATION-1ALogging is occurring for assets that are important to the delivery of the function, at least in an ad hoc mannerC2M2-SITUATION-1BLogging is occurring for assets within the function that may be leveraged to achieve a threat objective, wherever feasibleC2M2-SITUATION-1CLogging requirements are established and maintained for IT and OT assets that are important to the delivery of the function and assets within the function that may be leveraged to achieve a threat objectiveC2M2-SITUATION-1DLogging requirements are established and maintained for network and host monitoring infrastructure (for example, web gateways, endpoint detection and response software, intrusion detection and prevention systems)C2M2-SITUATION-1ELog data are being aggregated within the functionC2M2-SITUATION-1FMore rigorous logging is performed for higher priority assets