Skip to content
arrow_back
search
ISM-1989 policy ASD Information Security Manual (ISM)

Ensure Event Logs Meet Retention Requirements

Event logs must be kept according to the retention rules set by the National Archives of Australia.

record_voice_over

Plain language

This control ensures that you keep important event logs—records of what happens in your systems—according to rules from the National Archives of Australia. This is crucial because without these records, you might not be able to investigate issues or respond to incidents, potentially leading to non-compliance with regulations or loss of trust from your customers.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Event logs are retained as per minimum retention requirements for various classes of records as set out by the National Archives of Australia's Administrative Functions Disposal Authority Express (AFDA Express) Version 2 publication.
policy ASD Information Security Manual (ISM) ISM-1989
priority_high

Why it matters

If event logs are not retained to AFDA Express V2 minimum periods, investigations and audits may lack evidence, causing disposal breaches and compliance action.

settings

Operational notes

Regularly confirm log retention periods match AFDA Express V2 record classes, and ensure archived logs are protected, searchable, and retrievable for audits.

Mapping detail

Mapping

Direction

Controls