Skip to content
arrow_back
search
ISM-1906 policy ASD Information Security Manual (ISM)

Timely Analysis of Internet-Facing Server Logs

Organisations must quickly review logs from online servers to spot potential security threats.

record_voice_over

Plain language

This control is about regularly checking the records or logs from your online servers to quickly spot any security issues, like unauthorised access or attacks. If you don't do this, you might miss signs of a cyber threat, which could lead to loss of data, financial loss, or damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events.
policy ASD Information Security Manual (ISM) ISM-1906
priority_high

Why it matters

Without timely analysis of internet-facing server logs, intrusions may go unnoticed, delaying containment and increasing breach impact.

settings

Operational notes

Configure alerts for suspicious internet-facing server log events and review flagged entries within 24 hours to detect and respond quickly.

Mapping detail

Mapping

Direction

Controls