Skip to content
arrow_back
search
ISM-0582 policy ASD Information Security Manual (ISM)

Central Logging of Windows Security Events

Important Windows security events are collected in a central location to monitor system activities.

record_voice_over

Plain language

This control means collecting important security events from all Windows computers in one central spot. It's like having a single dashboard to see any unusual activity on your systems. If you don't do this, you might miss signs that someone is trying to hack into your network, which could lead to data breaches or other security problems.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Security-relevant events for Microsoft Windows operating systems are centrally logged.
policy ASD Information Security Manual (ISM) ISM-0582
priority_high

Why it matters

Without central logging of Windows Security events (e.g., logons, privilege use), attacks may not be correlated across hosts, delaying response and increasing breach likelihood.

settings

Operational notes

Configure Windows Security Event Log forwarding (e.g., WEF/agent) to a central SIEM, validate coverage, and alert on failed logons, privilege changes and audit policy tampering.

Mapping detail

Mapping

Direction

Controls