Skip to content
arrow_back
search
ISM-1976 policy ASD Information Security Manual (ISM)

Central Logging of Security Events on macOS

Ensure security events on macOS systems are logged centrally for monitoring.

record_voice_over

Plain language

This control means that important security-related activities on your Apple computers (macOS) should be reported to a central location so they can be closely watched. This is vital because if these activities are not tracked, you might miss signs of a cyber attack, which could lead to data loss or damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Security-relevant events for Apple macOS operating systems are centrally logged.
policy ASD Information Security Manual (ISM) ISM-1976
priority_high

Why it matters

Without central logging of macOS security events, threats may go unnoticed, leading to potential breaches and data theft.

settings

Operational notes

Regularly confirm macOS security logs are forwarded to the central log server/SIEM; investigate gaps, failed forwarding, and time sync issues promptly.

Mapping detail

Mapping

Direction

Controls