Skip to content
arrow_back
search
ISM-1889 policy ASD Information Security Manual (ISM)

Central Logging of Command Line Events

Track all command line actions by keeping a central log of every new process initiated via the command shell.

record_voice_over

Plain language

Central logging of command line actions is about keeping a record of every new task a computer starts through typing commands. This matters because without these logs, unauthorised activities might go unnoticed, putting your important information at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Command line process creation events are centrally logged.
policy ASD Information Security Manual (ISM) ISM-1889
priority_high

Why it matters

Without central logging of command line process creation, attackers can run commands without trace, delaying detection, investigation and containment.

settings

Operational notes

Forward command line process creation logs to a central SIEM and alert on suspicious parent/child process chains, unusual shells and admin tools.

Mapping detail

Mapping

Direction

Controls