Skip to content
arrow_back
search
E8-MF-ML3.4 bolt ASD Essential Eight

Analyse event logs from non-internet-facing servers timely to detect security events

Regularly check event logs from internal servers to catch security issues quickly.

record_voice_over

Plain language

Analysing event logs from internal servers regularly helps us catch signs of cyberattacks early. Without this practice, we might miss warning signs of someone trying to break into our systems, which could lead to data breaches and other serious security issues.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Multi-factor authentication

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.
bolt ASD Essential Eight E8-MF-ML3.4
priority_high

Why it matters

If logs on non-internet-facing servers aren’t reviewed promptly, lateral movement and credential misuse may be missed, delaying detection of internal breaches.

settings

Operational notes

Define review cadence and alerts for non-internet-facing server logs; centralise to SIEM, tune rules, and investigate anomalies within agreed timeframes.

Mapping detail

Mapping

Direction

Controls