Skip to content
arrow_back
search
E8-AC-ML2.7 bolt ASD Essential Eight

Event logs from internet-facing servers are analysed to detect cybersecurity events

Review logs from internet servers quickly to spot any security issues.

record_voice_over

Plain language

This control is about regularly reviewing the logs from servers that are accessible from the internet to catch any signs of cyber attacks quickly. By doing this, organisations can spot suspicious activities early and respond before they cause serious harm, like stealing sensitive data or crashing their website.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Application control

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events.
bolt ASD Essential Eight E8-AC-ML2.7
priority_high

Why it matters

If logs from internet-facing servers aren’t analysed promptly, intrusions can go unnoticed longer, increasing data theft and service disruption risk.

settings

Operational notes

Centralise internet-facing server logs in a SIEM, set anomaly alerts, and review/investigate critical events daily to ensure timely detection.

Mapping detail

Mapping

Direction

Controls