Skip to content
arrow_back
search
ISM-1907 policy ASD Information Security Manual (ISM)

Timely Analysis of Non-Internet-Server Logs

Examine logs from servers not facing the internet promptly to find security issues.

record_voice_over

Plain language

This control is about making sure that logs from servers that aren't directly connected to the internet are looked at quickly. It's important because these logs can reveal hidden security threats or unusual activity, and if not checked regularly, problems could go unnoticed until they cause significant damage.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.
policy ASD Information Security Manual (ISM) ISM-1907
priority_high

Why it matters

If non-internet-facing server logs aren’t analysed promptly, internal compromise and lateral movement may go unnoticed, delaying detection and response.

settings

Operational notes

Analyse non-internet-facing server logs daily (or per risk), use alerting for suspicious events, and document triage and escalation timelines.

Mapping detail

Mapping

Direction

Controls