INTRA/MD/MD002Log collection and centralization
The aggregation of records of activity from systems across the estate into a single store.
| Control | Jurisdiction | Source | What it establishes | Prerequisite or recommendation |
|---|---|---|---|---|
| MD002/EUMandatory | European Union | Commission Implementing Regulation (EU) 2024/2690European Commission · read 29 Aug 2026 | What the directive’s categories hold, in an annex setting out asset classification, the inventory, access control, privileged accounts, and removable media as requirements rather than as headings. | For the digital infrastructure and service providers it reaches, the list of assets to be logged is derived from the risk assessment, and what the logs hold is named: inbound and outbound traffic, the creation, modification, and deletion of users and the extension of their permissions, access to systems and applications, authentication events, all privileged access and everything done by administrative accounts, access or changes to critical configuration and backup files, physical access to facilities, and the activation, stopping, and pausing of the logs themselves. They are kept for a period fixed in advance and protected from unauthorized access or change, time sources are synchronized so that logs can be correlated across systems, and the availability of the logging systems is monitored independently of the systems they log. |
| MD002/ITMandatory | Italy | Determinazione ACN n. 379907 del 18 dicembre 2025Agenzia per la cybersicurezza nazionale · read 29 Aug 2026 | The baseline security measures an Italian NIS subject has to adopt, among them the recording of remote and administrative access and its central retention, the detection of privilege abuse, and the vetting of the people admitted to the systems that matter. | For a subject in the national NIS register, all remote access and all access made with administrative privileges are recorded. For the systems that matter, the logs needed to monitor security events are acquired and kept securely and, where it can be done, centrally, and how long they are kept is fixed from the risk assessment and documented. |
| MD002/ESMandatory | Spain | Real Decreto 311/2022, Esquema Nacional de SeguridadGobierno de España · read 29 Aug 2026 | The security measures a Spanish public sector body has to apply, graded by category, among them the concurrence of two people on critical tasks so that no single authorized individual can abuse their rights, an access control on the activity records themselves, and the recording of evidence where an incident may end in disciplinary action. | The audit record carries at least the identifier of the user or entity the event belongs to, the date and time, what information the event was performed on, the type of event, and whether it succeeded or failed. Above the low level the security documentation states which events are audited and how long the records are kept before deletion, the clock is an administration function protected by authentication and integrity, and the records and their backups may be reached or deleted only by duly authorized personnel. |
| Recommended | Austriawhere written | Österreichisches Informationssicherheitshandbuch 4.4.0Bundeskanzleramt und A-SIT · read 29 Aug 2026 | That logging is only effective as a security measure once someone independent reads it, that where nobody independent can, the administrators’ own activity is what stops being checkable, and that the evaluation goes before the data protection officer either way. | Logging security relevant events works as a security measure only where the data are evaluated at regular intervals by an independent reviewer. Where no independent reviewer can be put in place the administrators may do it, and the handbook states the consequence rather than leaving it: checking the administrators’ own activity then becomes hard. The evaluation is to be laid before the data protection officer or the security officer in any case, the responsibility for carrying it out is to be fixed exactly, the four eyes principle should be used in the security critical cases, and it must be ensured by technical or organizational means that the administrators’ activities can be adequately checked. |
| Recommended | Belgiumwhere written | CyberFundamentals 2025, EssentialCentre for Cybersecurity Belgium · read 29 Aug 2026 | What the Belgian centre sets out for the heaviest of its assurance levels, and the only place in this record where a national authority names the insider as something the detection tools are there to catch. | The logging functionality of the protection and detection tools is enabled, the logs are backed up and kept for a period fixed in advance, and they are reviewed regularly for unusual or potentially harmful activity, on a documented procedure. |
| Recommended | Finlandwhere written | Katakri 2020Kansallinen turvallisuusviranomainen · read 29 Aug 2026 | The criteria an authority audits against, among them the requirement to recognize which functions call for special trustworthiness, a clearance graded on three scales, and log retention set by the limitation periods of the criminal law. | The retention follows what the records may later have to answer. At the fourth classification level the essential recordings are kept at least six months; where the limitation periods of the criminal law bear on the information, at least five years, which is also the floor at the two levels above. The clocks within a security domain are synchronized to a single reference, the log files are backed up, a procedure covers their integrity, and they and the register services are protected against unauthorized access. |
| Recommended | Francewhere written | Guide d'hygiène informatiqueAgence nationale de la sécurité des systèmes d'information · read 29 Aug 2026 | Forty two measures at a standard and a reinforced level, among them the joining, leaving, and function change procedures written with the human resources function, and a minimum retention of one year for security critical events. | The critical components are determined first, the workstations of sensitive users named among them, and the logging on each is configured to match. Security critical events are kept for at least a year, or longer where the sector’s legal obligations require it, and the time synchronization source is the same across components so that events can be correlated. At the reinforced level the logs are centralized on a dedicated device, which is wanted for three reasons: automated searching, long archiving, and preventing an attacker from erasing the traces of their passage on what they compromised. |
| Recommended | Germanywhere written | IT-Grundschutz-Kompendium, Edition 2023Bundesamt für Sicherheit in der Informationstechnik · read 29 Aug 2026 | What the German federal authority holds to be the state of the art, in numbered requirements, among them the checking of a candidate’s own account of themselves, a logging infrastructure the administrators who run it cannot alter, a regular audit of the detection systems against the state they are supposed to be in, and how evidence is secured. | A logging policy of its own is drawn up, saying how, where, and what is logged, with the kind and the extent of it following the protection the information needs. All security relevant events on systems and applications are logged, the clocks of everything that logs are kept synchronized and the date and time format made uniform, and it is checked at defined intervals that the logging still works. Data protection law and the co-determination rights of the workforce representation are to be kept to, logging data are deleted on a defined process, and their uncontrolled deletion or alteration is prevented technically. The data should be held centrally, on a log server assembly in a network segment set up for it, and filtered, normalized, aggregated, and correlated for evaluation while a copy is kept in unaltered original form. The administrators who run it should have no entitlement to change or delete what has been recorded. |
| Recommended | Netherlandswhere written | Baseline Informatiebeveiliging Overheid 2, versie 1.3Nederlandse overheid · read 29 Aug 2026 | The government measures Dutch public bodies add on top of the two information security standards, among them a screening policy, a detection use case named in the text, and a log retention set against the scenario that an attacker has been inside for a long time. | There is an overview of the log files that are generated. How long the log files and the data in the security information and event monitoring are kept is settled against the risk, and the scenario it is settled against is named: that the attackers have been inside for a long time. Improper alteration or deletion of log data, and any attempt at it, is reported as soon as it can be. |
| Recommended | Norwaywhere written | NSMs grunnprinsipper for IKT-sikkerhet 2.1Nasjonal sikkerhetsmyndighet · read 29 Aug 2026 | A set of principles for securing information systems, with the monitoring ones carrying what the collected data may be used for, what employees are to be told about it, and the requirement to verify that the collection is working. | A written strategy for security monitoring settles the purpose and the field of use of what is collected, which data are collected, their secure storage including for legal proceedings, capacity planning, who may reach them, the consolidation of logs from the different units and services, deletion, and the interval at which the strategy is reviewed, at least once a year and after a major incident. What is collected is verified against what was meant to be, the data are archived and digitally signed at intervals for integrity, functionality is put in place that detects attempts to alter or delete a log, everything is synchronized to one and the same time source, and what has lost its operational or security relevance is removed. |
