Skip to content
arrow_back
search
ISM-1624 policy ASD Information Security Manual (ISM)

Protect PowerShell Script Block Logs

PowerShell logs are safeguarded by secure event logging that ensures their protection.

record_voice_over

Plain language

PowerShell is a tool often used to automate tasks on computers. If someone with bad intentions gets access to your system, they could use PowerShell to cause harm without you knowing. Protecting PowerShell logs ensures that any activity is recorded and cannot be tampered with, helping to detect and prevent misuse.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

PowerShell script block logs are protected by Protected Event Logging functionality.
policy ASD Information Security Manual (ISM) ISM-1624
priority_high

Why it matters

If PowerShell script block logs are not protected with Protected Event Logging, attackers can tamper with or hide executed scripts, delaying detection and enabling compromise.

settings

Operational notes

Confirm Protected Event Logging is enabled and uses the correct certificate; routinely validate that PowerShell Script Block Logging events are being recorded and are not writable by users.

Mapping detail

Mapping

Direction

Controls