What you need to know
Current joint guidance centers effective logging on approved policy, centralized collection and correlation, protected log integrity, and detections designed for relevant threats.
Potentially affected
Organizations collecting security events from identity, endpoint, network, application, cloud, mobile, or operational-technology environments.
DSE recommendation
Approve the logging purpose and scope, inventory high-value sources, normalize time, centralize and protect events, build relevant detections, and test the complete alert path.
Logs become security evidence only when the organization knows why they are collected, can correlate them, protects their integrity, and turns relevant activity into a tested response. Collecting everything without ownership can increase cost while leaving important gaps unnoticed.
Four practices in the joint guidance
Source fact: CISA and international partners published event-logging and threat-detection guidance for cloud services, enterprise information-technology networks, enterprise mobility, and operational-technology networks. The intended audience includes senior IT decision makers, security practitioners, IT managers, OT operators, and network administrators.
Source fact: The guidance identifies four central considerations: an enterprise-approved event-logging policy; centralized log collection and correlation; secure storage and log integrity; and a detection strategy for relevant threats. It also highlights consistent event content, formats, and timestamps as important to useful analysis.
Define the evidence before the platform
DSE recommendation: approve the business and security purpose of logging before selecting retention or storage architecture. Record the environments and sources in scope, accountable owners, required events and context, access restrictions, time standard, retention basis, review expectations, privacy considerations, provider responsibilities, and disposal process.
- Inventory identity, administrator, endpoint, server, application, cloud, firewall, network-device, DNS, remote-access, mobile, and relevant OT sources.
- Prioritize events that can establish authentication, privilege, configuration change, execution, network movement, data access, service health, and defensive-control activity.
- Normalize timestamps and preserve source, user, device, action, result, and correlation context where the system can provide it.
- Centralize high-value events and monitor for delayed, malformed, duplicated, or stopped ingestion.
- Restrict and monitor access, protect events from alteration and deletion, and maintain recovery appropriate to the evidence requirement.
Prove detection and response
DSE recommendation: define detections from credible threats and the organization’s environment, not from an unreviewed vendor default list. For each detection, name the expected data, logic, owner, urgency, investigation context, escalation, safe test, and review date. Run a known-safe test from source event through collection, correlation, alert, triage, and response. A visible source log does not prove the alert path works.
Applicability and limits
The joint publication is a baseline, not a universal event list, storage design, or retention schedule. Privacy, employment, legal, contractual, regulatory, safety, cost, and system-capacity requirements vary. OT and safety systems may require vendor-approved methods and careful testing. Logs can support an investigation but may be incomplete, inaccurate, compromised, or insufficient on their own.
Official reference
Best Practices for Event Logging and Threat Detection — joint baseline for policy, centralization, integrity, and detection.
Review the official source
CISA: Best Practices for Event Logging and Threat Detection · Published August 21, 2024
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE