Build event logging that supports detection, investigation, and resilience

Current joint guidance centers effective logging on approved policy, centralized collection and correlation, protected log integrity, and detections designed for relevant threats.

Executive summary

What you need to know

Current joint guidance centers effective logging on approved policy, centralized collection and correlation, protected log integrity, and detections designed for relevant threats.

Potentially affected

Organizations collecting security events from identity, endpoint, network, application, cloud, mobile, or operational-technology environments.

DSE recommendation

Approve the logging purpose and scope, inventory high-value sources, normalize time, centralize and protect events, build relevant detections, and test the complete alert path.

Logs become security evidence only when the organization knows why they are collected, can correlate them, protects their integrity, and turns relevant activity into a tested response. Collecting everything without ownership can increase cost while leaving important gaps unnoticed.

Four practices in the joint guidance

Source fact: CISA and international partners published event-logging and threat-detection guidance for cloud services, enterprise information-technology networks, enterprise mobility, and operational-technology networks. The intended audience includes senior IT decision makers, security practitioners, IT managers, OT operators, and network administrators.

Source fact: The guidance identifies four central considerations: an enterprise-approved event-logging policy; centralized log collection and correlation; secure storage and log integrity; and a detection strategy for relevant threats. It also highlights consistent event content, formats, and timestamps as important to useful analysis.

Define the evidence before the platform

DSE recommendation: approve the business and security purpose of logging before selecting retention or storage architecture. Record the environments and sources in scope, accountable owners, required events and context, access restrictions, time standard, retention basis, review expectations, privacy considerations, provider responsibilities, and disposal process.

  1. Inventory identity, administrator, endpoint, server, application, cloud, firewall, network-device, DNS, remote-access, mobile, and relevant OT sources.
  2. Prioritize events that can establish authentication, privilege, configuration change, execution, network movement, data access, service health, and defensive-control activity.
  3. Normalize timestamps and preserve source, user, device, action, result, and correlation context where the system can provide it.
  4. Centralize high-value events and monitor for delayed, malformed, duplicated, or stopped ingestion.
  5. Restrict and monitor access, protect events from alteration and deletion, and maintain recovery appropriate to the evidence requirement.

Prove detection and response

DSE recommendation: define detections from credible threats and the organization’s environment, not from an unreviewed vendor default list. For each detection, name the expected data, logic, owner, urgency, investigation context, escalation, safe test, and review date. Run a known-safe test from source event through collection, correlation, alert, triage, and response. A visible source log does not prove the alert path works.

Applicability and limits

The joint publication is a baseline, not a universal event list, storage design, or retention schedule. Privacy, employment, legal, contractual, regulatory, safety, cost, and system-capacity requirements vary. OT and safety systems may require vendor-approved methods and careful testing. Logs can support an investigation but may be incomplete, inaccurate, compromised, or insufficient on their own.

Official reference

Best Practices for Event Logging and Threat Detection — joint baseline for policy, centralization, integrity, and detection.

Primary reference

Review the official source

CISA: Best Practices for Event Logging and Threat Detection · Published August 21, 2024

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE