Skip to content
arrow_back
E8-AH-ML2.15boltASD Essential Eight

Timely Analysis of Cyber Security Events to Identify Incidents

Quickly review cyber events to find and manage security threats.

record_voice_over

Plain language

This control is about making sure that any suspicious activities or security alerts are looked at quickly. It's important because if a threat isn't caught in time, it could lead to data breaches, loss of money, or damage to your business's reputation.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

18 June 2026

E8 maturity levels

ML2

Official control statement

Cyber security events are analysed in a timely manner to identify cyber security incidents.
boltASD Essential EightE8-AH-ML2.15
priority_high

Why it matters

Delayed analysis of cyber events can leave threats undetected, leading to data breaches or financial loss if incidents aren't swiftly identified.

settings

Operational notes

Prioritise alerts by impact and confidence; use automated triage and defined escalation SLAs so events are reviewed quickly and incidents identified early.

build

Implementation tips

  • Security officer: Ensure the security team has clear procedures for regularly checking security alerts and logs. This can be done by scheduling daily or weekly reviews of alerts generated by systems.
  • IT manager: Set up automated alerts within your security software to notify the team of any unusual activity immediately. Use built-in alert settings provided by your security tools.
  • IT support staff: Train the IT team on how to recognise suspicious events and what steps to take if something unusual is detected. Organise regular training sessions with real-world examples.
  • Business owner: Ensure there's a designated person or team responsible for handling security alerts promptly. Communicate the importance of this role and include it in their job description.
fact_check

Audit / evidence tips

  • AskHow quickly are security alerts typically reviewed by your team?
  • GoodThe team reviews and addresses security alerts within defined timeframes, usually within 24 hours, with logs showing prompt responses
  • AskWhat procedures are in place to ensure timely analysis of cybersecurity events?
  • GoodThere are documented procedures outlining steps for analysing and responding to security events within 24 hours
link

Cross-framework mappings

How E8-AH-ML2.15 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(2)expand_less
Annex A 5.25E8-AH-ML2.15 requires cyber security events to be analysed in a timely manner so they can be identified and treated as incidents
Annex A 8.16E8-AH-ML2.15 requires cyber security events to be analysed timely to identify incidents
handshakeSupports(1)expand_less
Annex A 8.17E8-AH-ML2.15 requires timely analysis of cyber security events to identify incidents
extensionDepends on(1)expand_less
Annex A 8.15E8-AH-ML2.15 requires timely analysis of cyber security events to identify incidents

ASD ISM

ControlNotesDetails
layersPartially meets(1)expand_less
ISM-2089ISM-2089 requires organisations to monitor AI model performance metrics and investigate anomalies
handshakeSupports(6)expand_less
ISM-0660ISM-0660 requires organisations to fully verify data transfer logs for SECRET and TOP SECRET systems at least monthly to ensure transfers...
ISM-1526ISM-1526 requires ongoing monitoring of systems and associated cyber threats, security risks and controls by system owners
ISM-1556ISM-1556 requires post-travel monitoring for compromise indicators
ISM-1625ISM-1625 requires an insider threat mitigation program that includes detection and triage of suspicious internal behaviour and misuse
ISM-1683ISM-1683 requires successful and unsuccessful MFA events to be centrally logged
ISM-2117ISM-2117 requires suitable AI models to augment detection of cyber security events and identification of incidents
extensionDepends on(5)expand_less
ISM-0120E8-AH-ML2.15 requires organisations to analyse cyber security events in a timely manner to identify incidents
ISM-0634E8-AH-ML2.15 requires timely analysis of cyber security events to identify incidents
ISM-1030E8-AH-ML2.15 requires organisations to analyse cyber security events in a timely manner to identify incidents
ISM-1830E8-AH-ML2.15 requires timely analysis of cyber security events to identify incidents
ISM-1911E8-AH-ML2.15 requires timely analysis of cyber security events to identify incidents
linkRelated(2)expand_less
ISM-1228E8-AH-ML2.15 requires cyber security events to be analysed in a timely manner to identify cyber security incidents
ISM-1986E8-AH-ML2.15 requires timely analysis of cyber security events to identify incidents

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all User application hardening controls, or browse the full Essential Eight library.

Mapping detail

Mapping

Direction

Controls