Timely Analysis of Workstation Event Logs
Workstation event logs must be checked promptly to find any cybersecurity issues.
Plain language
Checking the logs on your office computers regularly can help you spot any suspicious activity, like a hacker trying to get in. If you ignore these logs, you might miss a sign that someone is tampering with your system, which could lead to data breaches or other security issues.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Dec 2023
Control Stack last updated
18 June 2026
E8 maturity levels
ML3
Official control statement
Event logs from workstations are analysed in a timely manner to detect cyber security events.
Why it matters
Without regular log checks, cyber incidents may go unnoticed, leading to data breaches and operational disruptions.
Operational notes
Consistent log reviews are key; set reminders and allocate specific staff to ensure they are thoroughly checked.
Implementation tips
- The IT team should assign a staff member to regularly review workstation event logs. They can set a schedule to check these logs daily or weekly to quickly spot any unusual activity.
- Office managers should ensure that IT staff have the tools they need to access and understand event logs. This could include basic training on what sorts of events to look out for, like repeated login failures.
- Small business owners should consider investing in log analysis software. This software can help automate the process, flagging patterns that might indicate a security issue, saving time for the IT staff.
- Managers should discuss with their team how to report findings from log checks. Create a simple process, like an email or quick meeting, to address any issues immediately.
- HR can help maintain communication by ensuring everyone in the office understands the importance of log monitoring. They should organise periodic reminders or training sessions about recognising and reporting unusual activity.
Audit / evidence tips
- Aska log review schedule document: Request a copy of the timetable showing when logs are reviewedLook atregular, consistent times set for analysisGoodis a clear, documented schedule that staff are following
- Askrecent log review reports: Request a report on recent log findingsLook atwhether it details events noted and actions takenGoodincludes specific incidents identified and what was done about them
- Askevidence of training sessions: Request records of recent training that staff attended on log analysisLook atattendance lists and training materialsGoodincludes proof that staff know what to look for in logs
- Asksoftware usage records: Request documentation showing what log analysis software is usedLook atlicenses and usage logsGoodincludes up-to-date software details that employees regularly use for their checks
- Askto see incident follow-up records: Request records of how issues found in logs were resolvedLook atincident reports with actions takenGoodshows that issues identified in logs are taken seriously and fixed promptly
Cross-framework mappings
How ISM-0109 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.14 | ISM-0109 requires confirming all members’ nationalities before sending sensitive Australian data to email distribution lists, to prevent ... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Security assurance
See all Guidelines for security assurance controls, or browse the full ASD ISM library.