BlogMay 24, 2024InfusionPoints

Log Architecture Maturity Assessment for M-21-31

What is M-21-31?M-21-31, Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incidents, is a memorandum published by the US…

Log Architecture Maturity Assessment for M-21-31

What is M-21-31?

M-21-31, Improving the Federal Government’s Investigative and Remediation Capabilities Related to Cybersecurity Incidents, is a memorandum published by the US Office of Management and Budget (OMB) in August of 2021, which was developed in accordance with and addresses the requirements in Section 8 of Executive Order 14028, Improving the Nation's Cybersecurity. It defines event logging requirements for federal agencies related to cybersecurity incidents, the log data that must be captured for various log categories, and details the requirements for detection, investigation, & remediation of cyber incidents. The memorandum also includes a 4-tiered Event Logging (EL) implementation Maturity Model for agencies to follow and gives a deadline for agencies to achieve each EL tier.

4 Event Logging (EL) Tiers

Event Logging Tiers

Rating 

Description

EL0

Not Effective

Logging requirements of highest criticality are either not met or are only partially met

EL1

Basic 

Only logging requirements of highest criticality are met

EL2

Intermediate

Logging requirements of highest and intermediate criticality are met

EL3

Advanced

Logging requirements at all criticality levels are met

Continuous Trust

Ready to reduce audit drag and prove trust continuously?

InfusionPoints helps regulated cloud teams build, operate, prove, and defend environments across FedRAMP, DoW, CMMC, and agency mission needs.