Skip to content
arrow_back
search
E8-AH-ML3.4 bolt ASD Essential Eight

Analyze event logs from non-internet-facing servers for cyber threats

Regularly check server logs not exposed to the internet for signs of hacking.

record_voice_over

Plain language

This control is about regularly checking the logs of servers that aren't connected to the internet to spot any signs of hacking or cyber threats. It's important because even though these servers are not directly exposed to online threats, they could still be at risk from insiders or malware that sneaks in through other means. If we don’t study these logs, a cyber attack might go unnoticed until it’s too late.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Event logs from non-internet-facing servers are analyzed in a timely manner to detect cyber security events.
bolt ASD Essential Eight E8-AH-ML3.4
priority_high

Why it matters

Failure to analyse event logs on non-internet-facing servers can allow internal compromise to persist unnoticed, causing data loss and disruption.

settings

Operational notes

Centralise non-internet-facing server logs in a SIEM, alert on anomalies, and review alerts daily (not weekly) to detect threats promptly.

Mapping detail

Mapping

Direction

Controls