Skip to content
arrow_back
search
ISM-1988 policy ASD Information Security Manual (ISM)

Ensure Event Logs Are Retained for 12 Months

Keep event logs searchable and accessible for at least 12 months to help in audits or investigations.

record_voice_over

Plain language

Keeping digital event logs for at least 12 months means that any records of activities on your computer systems remain accessible for a year, helping you to look into any suspicious behaviour or satisfy regulatory checks. If you don't keep these logs, you might miss critical clues needed to investigate a problem or prove compliance.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Event logs are retained in a searchable manner for at least 12 months.
policy ASD Information Security Manual (ISM) ISM-1988
priority_high

Why it matters

Without 12-month log retention, critical incident traces can be lost, hampering investigations and regulatory compliance efforts.

settings

Operational notes

Configure systems to retain searchable event logs for 12 months; periodically test log search and verify retention settings to support investigations and audits.

Mapping detail

Mapping

Direction

Controls