Skip to content
arrow_back
boltASD Essential Eight

Essential Eight RA-ML2.6Privileged access events are centrally logged.

Keep logs of admin actions in a central place to monitor for misuse.

record_voice_over

Plain language

Keeping track of what actions administrators take on computer systems is crucial. It's like having a CCTV system for your computer network. Without these records, if someone misuses their high-level access, it would be difficult to catch them or understand what went wrong.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

18 June 2026

E8 maturity levels

ML2

Official control statement

Privileged access events are centrally logged.
boltASD Essential EightE8-RA-ML2.6
priority_high

Why it matters

Lack of central logs for privileged access can obscure unauthorised activities, risking undetected insider threats and hindering incident investigation.

settings

Operational notes

Forward privileged access logs to a central SIEM, monitor them continuously, and alert on unusual admin actions to enable timely detection and investigation.

build

Implementation tips

  • IT team should set up a central logging system to collect all admin activities by configuring the network to send logs to a secure server.
  • System administrators should ensure that all systems are configured to log privileged actions, like changes to system settings, by using the system's built-in logging features.
  • Security officers should regularly review these central logs to spot any unusual activities that might indicate misuse, by setting up a schedule for log analysis.
  • The IT manager should implement alerts for any known risky activities, such as failed login attempts or changes outside of business hours, by configuring the logging system's alerting functions.
fact_check

Audit / evidence tips

  • AskHow are privileged access events logged in your organisation?
  • GoodThe system should automatically log all privileged access events and send them to a secure, central logging system which is regularly reviewed
  • AskWho regularly checks the central logs for unusual activities?
  • GoodThere should be a clear schedule of log reviews, and any findings should be documented and acted upon
link

Cross-framework mappings

How E8-RA-ML2.6 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.15E8-RA-ML2.6 requires privileged access events to be centrally logged to enable monitoring and investigation of administrative misuse
handshakeSupports(1)expand_less
Annex A 8.16E8-RA-ML2.6 requires privileged access events to be centrally logged to allow oversight and detection of misuse

ASD ISM

ControlNotesDetails
layersPartially meets(4)expand_less
ISM-0670ISM-0670 requires security-relevant events for CDSs to be centrally logged
ISM-1613E8-RA-ML2.6 requires organisations to centrally log privileged access events to support detection of misuse
ISM-1650E8-RA-ML2.6 requires central logging of privileged access events across the environment to enable monitoring for misuse
ISM-1830ISM-1830 requires security-relevant events for Microsoft AD DS domain controllers, AD CS CA servers, AD FS servers and Microsoft Entra Co...
sync_altPartially overlaps(8)expand_less
ISM-0582ISM-0582 requires that security-relevant events for Microsoft Windows operating systems are centrally logged
ISM-0585ISM-0585 requires consistent per-event fields such as who/what initiated an action, when it occurred, and which system and object were in...
ISM-1537ISM-1537 requires organisations to centrally log security-relevant database events, including privileged user activity such as DBA action...
ISM-1607ISM-1607 mandates integrity monitoring and centralised event logging for isolation mechanisms and host OS on shared servers
ISM-1895ISM-1895 requires central logging of successful and unsuccessful single-factor authentication events
ISM-1976ISM-1976 requires central logging of security-relevant events on macOS endpoints
ISM-1977E8-RA-ML2.6 requires privileged access events to be centrally logged to detect and investigate misuse of elevated access
ISM-1989ISM-1989 requires event logs to be retained according to AFDA Express minimum retention requirements
handshakeSupports(3)expand_less
ISM-0415E8-RA-ML2.6 requires privileged access events to be centrally logged to detect misuse and support attribution
ISM-0580E8-RA-ML2.6 requires privileged access events to be centrally logged as an operational control to enable monitoring and detection
ISM-1983ISM-1983 requires event logs to be sent to a centralised event logging facility as soon as possible after they occur
linkRelated(1)expand_less
ISM-1509E8-RA-ML2.6 requires that privileged access events are centrally logged so privileged activity can be monitored for misuse

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Restrict admin privileges controls, or browse the full Essential Eight mitigation strategies library.

Mapping detail

Mapping

Direction

Controls