Skip to content
arrow_back
search
E8-RA-ML3.8 bolt ASD Essential Eight

Timely analysis of event logs from non-internet-facing servers

Review logs of internal servers promptly to spot security threats.

record_voice_over

Plain language

This control is about quickly checking the activity logs of your internal servers that don't connect to the internet. It's important because it helps you catch any unusual or harmful behaviour, which could indicate a security problem, before it becomes a bigger issue.

Framework

ASD Essential Eight

Control effect

Detective

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.
bolt ASD Essential Eight E8-RA-ML3.8
priority_high

Why it matters

Unchecked internal server logs can conceal attacker footprints, enabling undetected lateral movement and privilege abuse, which jeopardises sensitive data.

settings

Operational notes

Review non-internet-facing server logs daily via SIEM/alerts, triaging auth failures, new admin accounts, service changes and lateral movement indicators.

Mapping detail

Mapping

Direction

Controls