MIL1 requirements
a. Logging is occurring for assets that are important to the delivery of the function, at least in an ad hoc manner
MIL2 requirements
b. Logging is occurring for assets within the function that may be leveraged to achieve a threat objective, wherever feasible
c. Logging requirements are established and maintained for IT and OT assets that are important to the delivery of the function and assets within the function that may be leveraged to achieve a threat objective
d. Logging requirements are established and maintained for network and host monitoring infrastructure (for example, web gateways, endpoint detection and response software, intrusion detection and prevention systems)
e. Log data are being aggregated within the function
MIL3 requirements
f. More rigorous logging is performed for higher priority assets
The development of system logs must keep pace with the development of the system and enable, for example, the necessary resolution of incidents. In connection with the data system list, we describe for which systems we are responsible for the implementation of the logging. For these systems, we document: