Section 8 develops cybersecurity event log requirements across the federal government so that agencies can better detect intrusions, mitigate in-progress attacks, and determine the extent of damage. Agencies and their IT service providers will need to collect and maintain logging data and, when necessary, provide it upon request to federal cybersecurity leadership.
OMB will formulate policies for agencies to establish requirements around:
- The types of logs to maintain
- The time periods to retain the logs and other relevant data
- The time periods to enable recommended logging and security requirements
- Protecting logs by cryptographic methods to ensure integrity once collected and periodically verified against the hashes throughout their retention