Skip to content
arrow_back
search
ISM-1977 policy ASD Information Security Manual (ISM)

Central Logging of Linux System Events

Important Linux system events should be logged in a central location for security purposes.

record_voice_over

Plain language

This control is about making sure all important events happening on your Linux computers are recorded in one central place. It matters because if something goes wrong, like a security breach, you want to know exactly what happened and when. Without this logging, it would be challenging to spot issues or figure out how to fix them.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Security-relevant events for Linux operating systems are centrally logged.
policy ASD Information Security Manual (ISM) ISM-1977
priority_high

Why it matters

Without central logging of Linux security events, attacks may go undetected and incident investigation is slowed due to missing or scattered audit trails.

settings

Operational notes

Ensure Linux hosts forward security-relevant events (e.g. auth, sudo, kernel) to a central log server; monitor ingest health and review alerts for anomalies.

Mapping detail

Mapping

Direction

Controls