Skip to content
arrow_back
ISM-1961policyASD Information Security Manual (ISM)

Timely Analysis of Network Device Event Logs

Analyse logs from internal network devices quickly to detect security events.

record_voice_over

Plain language

This control is about regularly checking the logs from your organisation's network devices-like routers and switches-to spot any unusual or suspicious activity. If this isn't done, potential security threats could go unnoticed, leaving your business vulnerable to attacks or data breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2024

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Event logs from non-internet-facing network devices are analysed in a timely manner to detect cyber security events.
policyASD Information Security Manual (ISM)ISM-1961
priority_high

Why it matters

Failure to analyse network device logs promptly can allow undetected intrusions, leading to data breaches or loss of critical business assets.

settings

Operational notes

Review non-internet-facing network device event logs daily and alert on auth failures, config changes and unusual admin access; tune rules and escalate suspected incidents promptly.

build

Implementation tips

  • The IT team should regularly check logs from network devices to look for unusual patterns. This involves setting a schedule to review logs at least weekly and using tools that can highlight unexpected activity.
  • Managers should ensure that the IT team is trained to recognise potential security events in network logs. Arrange regular training sessions to keep the team updated on the latest threats and log analysis techniques.
  • The IT team should automate log analysis where possible using available tools. Set up automated alerts that notify the team of specific key indicators of potential breaches, saving time and increasing effectiveness.
  • A dedicated staff member should be assigned responsibility for log monitoring. Choose someone from the IT team to be the 'log champion'-this person will ensure daily reviews and be the first point of contact for any issues.
  • System owners should periodically meet with the IT team to review log findings. Arrange quarterly meetings to discuss any trends or patterns identified, and adjust security measures as needed.
fact_check

Audit / evidence tips

  • AskEvidence of log review schedules: Request the documented schedule of when log reviews occurGoodA clear log showing dates and times of reviews, occurring at least weekly
  • AskTo see the automated alert setup: Request a demonstration or screen captures showing automated alerts for log anomaliesGoodWell-configured alerts in line with organisational needs and risks
  • AskTraining records: Request certificates or internal records showing IT log analysis trainingGoodRecent and relevant training attended by all key IT staff
  • AskDocumentation of log review findings: Request reports or summaries from past log reviewsGoodClear reports highlighting findings and remedial actions
  • AskRecords of IT and management review meetings: Request minutes or notes from meetings between IT staff and management about log reviewsGoodRegular meetings with actionable conclusions documented
link

Cross-framework mappings

How ISM-1961 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

E8

ControlNotesDetails
layersPartially meets(1)expand_less
sync_altPartially overlaps(9)expand_less
linkRelated(1)expand_less

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for security assurance controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls