Skip to content
arrow_back
E8-AH-ML2.12boltASD Essential Eight

Command line process creation logging is centralised

Log all command line processes in a central location for monitoring.

record_voice_over

Plain language

This control is all about making sure that whenever something runs on a computer using a command line, a record of that action is saved in a central place. This is important because if something harmful were to happen, like a cyberattack or a virus, having these records helps us understand what's going on and how to fix it quickly.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

18 June 2026

E8 maturity levels

ML2

Official control statement

Command line process creation events are centrally logged.
boltASD Essential EightE8-AH-ML2.12
priority_high

Why it matters

Without centralised logging of command line process creation events, attacker-launched tools and scripts may not be detected or investigated in time.

settings

Operational notes

Enable command line process creation logging on endpoints/servers and forward events to a central SIEM; validate coverage, retention and integrity (e.g. hashing) regularly.

build

Implementation tips

  • The IT team must ensure that all computers are set to log command line events. This can be done by configuring the system to automatically send these logs to a central logging server.
  • System administrators should use group policy settings to enable command line process creation logging on Windows machines, making sure the settings apply to all relevant computers across the organisation.
  • The security officer should verify that the central logging system is capable of receiving logs from all networked computers by testing log transmission and reception regularly.
  • The IT team should implement automated alerts for unusual command line activities to promptly identify potential security incidents. This can be done by setting up monitoring rules in the logging system.
  • Regular training sessions for the IT team are essential, focusing on identifying unusual patterns in the logs that could indicate a security threat. This helps ensure the logs are effectively used for monitoring purposes.
fact_check

Audit / evidence tips

  • AskIs command line process creation logging enabled on all computers?
  • GoodThe group policy is set to log all command line process creation events, and these logs are being sent to the central logging system
  • AskHow are the logs being reviewed for unusual activity?
  • GoodLogs are automatically analysed, and the system sends alerts on detecting unusual activities, verified by recent test alerts for suspicious patterns
link

Cross-framework mappings

How E8-AH-ML2.12 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.15E8-AH-ML2.12 requires that command line process creation events are centrally logged
handshakeSupports(2)expand_less
Annex A 5.28E8-AH-ML2.12 requires centralised logging of command line process creation events, which can form an evidence trail of execution on systems
Annex A 8.16E8-AH-ML2.12 requires command line process creation events to be centrally logged, providing visibility of execution behaviour across end...

ASD ISM

ControlNotesDetails
layersPartially meets(2)expand_less
ISM-0670ISM-0670 requires central logging of security-relevant events for CDSs
ISM-1405E8-AH-ML2.12 requires centralised logging specifically for command line process creation events
sync_altPartially overlaps(2)expand_less
ISM-1607E8-AH-ML2.12 requires centralised logging of command line process creation events on hosts
ISM-1623E8-AH-ML2.12 requires that command line process creation events are centrally logged
handshakeSupports(9)expand_less
ISM-0580ISM-0580 requires an organisation to develop, implement and maintain an event logging policy to ensure events are recorded and monitored
ISM-0582E8-AH-ML2.12 requires centralised logging of command line process creation events to improve visibility of execution behaviour
ISM-0585E8-AH-ML2.12 requires central logging of command line process creation events
ISM-1228E8-AH-ML2.12 requires centralised logging of command line process creation events so that execution activity is available for monitoring
ISM-1907E8-AH-ML2.12 requires command line process creation events to be centrally logged, creating a reliable log source for server monitoring
ISM-1976E8-AH-ML2.12 requires centralised logging of command line process creation to detect suspicious execution
ISM-1977E8-AH-ML2.12 requires command line process creation events to be centrally logged
ISM-1986E8-AH-ML2.12 requires centralised logging of command line process creation events, which are commonly critical for detecting attacker tra...
ISM-2051E8-AH-ML2.12 requires organisations to centrally log command line process creation events
extensionDepends on(1)expand_less
ISM-1983E8-AH-ML2.12 requires centralised logging of command line process creation events, which is most valuable when logs arrive centrally quic...
linkRelated(1)expand_less
ISM-1889E8-AH-ML2.12 requires organisations to centrally log command line process creation events for monitoring and detection

ISO 42001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 6.2.6Annex A 6.2.6 requires the organisation to define and document ongoing AI system operation elements, including monitoring, repairs, updat...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all User application hardening controls, or browse the full Essential Eight library.

Mapping detail

Mapping

Direction

Controls