Skip to content
arrow_back
search
ISM-1623 policy ASD Information Security Manual (ISM)

Centralised Logging of PowerShell Activities

Ensure PowerShell actions and logs are collected in a central place for monitoring.

record_voice_over

Plain language

This control is about making sure all the actions and logs from PowerShell, a tool commonly used in Windows computers, are collected in a central spot. This matters because if you don't keep track of what's happening with PowerShell, you might miss signs that someone is trying to break into your computers or steal important data.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

PowerShell module logging, script block logging and transcription events are centrally logged.
policy ASD Information Security Manual (ISM) ISM-1623
priority_high

Why it matters

Without centralised logging of PowerShell module, script block and transcription events, malicious PowerShell use may go unnoticed, leading to compromise or data breach.

settings

Operational notes

Enable module logging, script block logging and transcription, forward events to a central SIEM, and routinely hunt for suspicious cmdlets, encoded commands and unusual scripts.

Mapping detail

Mapping

Direction

Controls