Skip to content
arrow_back
ISM-1983policyASD Information Security Manual (ISM)

Log Events Sent to Centralised Facility Quickly

Ensure all event logs are sent to a central logging facility as soon as possible after occurring.

record_voice_over

Plain language

This control means that when something important happens in your computer systems, a record of it should be sent to a central place as soon as possible. It matters because if there's a security issue, being able to see these records quickly can help stop or fix the problem before it becomes a big deal.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Event logs sent to a centralised event logging facility are sent as soon as possible after they occur.
policyASD Information Security Manual (ISM)ISM-1983
priority_high

Why it matters

Delayed logs can mean security incidents go unnoticed, leading to data breaches or system downtime.

settings

Operational notes

Regularly verify that logging systems are functioning and alarms trigger as expected to swiftly address any failures.

build

Implementation tips

  • IT team should ensure that logging settings are configured: Adjust settings so that all important activity logs from computers and systems are sent immediately to a central server. Use easy-to-understand instructions from your logging software vendor.
  • System owners should routinely verify log transmissions: Regularly check that logs are being sent to the central facility without delays. This can be done by randomly viewing log timestamps and cross-check with the central server.
  • Managers should discuss with IT about log management policies: Ensure there are clear rules about what needs to be logged and sent to the central server, and how quickly it should happen. Have clear communication channels for any adjustments needed.
  • IT team should set up automated alerts for failures: Use simple automatic notifications to know instantly if logs are not being sent as expected. These can be configured in the logging system preferences.
  • Compliance officers to conduct regular reviews: Every few months, go over the log data transfer process to ensure it aligns with company policy and any legal requirements. Update procedures if necessary to fix any gaps found.
fact_check

Audit / evidence tips

  • Asklog transmission reports: Request recent records showing when logs were sent to the central facilityLook atthe timestamps to ensure logs are sent promptlyGoodis showing logs are sent within minutes of creation
  • Askto see the logging configuration settings: Check if the systems are set up to send logs automatically to the central serverLook atsettings that indicate immediate or very frequent log transfersGoodis a screenshot or document confirming this
  • Askany incidents of delayed logging: Request incident logs that record any delays in sending logsLook atinvestigation notes on causes and fixesGoodis documented resolution steps with timeframes
  • Askto see notifications of log transmission failures: Request evidence of setup for alerts when logs fail to sendLook atlogs showing alerts were properly triggeredGoodshows consistent alerting without gaps
  • Aska demonstration of the logging process: Request a live demonstration of a recent log event and its path to the central systemLook atthe demonstration of how quickly it is processedGoodshows minimal delay
link

Cross-framework mappings

How ISM-1983 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.15ISM-1983 requires event logs to be sent to a centralised event logging facility as soon as possible after they occur

E8

ControlNotesDetails
handshakeSupports(3)expand_less
extensionDepends on(3)expand_less

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for security assurance controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls