Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

OMB Issues Updated Federal Cyber Logging Guidance

by Jane Edwards
May 26, 2026
in Cybersecurity, News
Office of Management and Budget logo. OMB has issued new guidance directing agencies to adopt a risk-based logging framework.

The Office of Management and Budget has released updated guidance directing agencies to adopt a risk-based logging framework focused on two priorities: continuous event monitoring; and threat hunting, investigation, response, and forensics.

  • OMB has issued updated federal cyber logging guidance focused on CEM and THIRF priorities
  • Agencies must submit logging plans after CISA releases new reference architecture
  • CISA will publish baseline requirements for centralized logging and threat detection

The Office of Management and Budget has released updated guidance directing agencies to adopt a risk-based logging framework focused on two priorities: continuous event monitoring, or CEM, and threat hunting, investigation, response and forensics, or THIRF.

Table of Contents

    • You might also like
    • Jay Clayton’s DNI Nomination Advances After Senate Panel Vote
    • White House OSTP Report Offers Recommendations to Revitalize R&D Enterprise
    • FCC Extends Drone Exceptions, Seeks Comment on Foreign Military-Grade Drone Ban
  • What Cybersecurity Priorities Should Agencies Focus On?
  • What Is the Agency Logging Plan?
  • What Are the Base Requirements for the Logging Reference Architecture?
  • What Are the Agency Implementation Deadlines?

You might also like

Jay Clayton’s DNI Nomination Advances After Senate Panel Vote

White House OSTP Report Offers Recommendations to Revitalize R&D Enterprise

FCC Extends Drone Exceptions, Seeks Comment on Foreign Military-Grade Drone Ban

In a memorandum published Friday, OMB said the latest guidance rescinds a 2021 policy that establishes a maturity model for event log management.

The memo came two months after the Trump administration released its cyber strategy that outlines a governmentwide effort to strengthen national cyber defenses while expanding offensive capabilities to counter foreign threats.

What Cybersecurity Priorities Should Agencies Focus On?

OMB directed agencies to prioritize two logging objectives: CEM and THIRF. Continuous event monitoring requires agencies to maintain logs and logging infrastructure that support real-time monitoring of network activity, rapid detection of anomalous behavior and timely incident response through security operations centers.

THIRF focuses on post-compromise analysis and recovery efforts. OMB said agencies must maintain sufficient hot and cold storage capabilities and ensure they can retrieve and centralize logs from multiple sources to identify attack patterns. The requirements apply to all federal information systems, including Internet of Things devices and operational technology environments.

What Is the Agency Logging Plan?

The memorandum directs agencies to submit an agency logging plan to OMB and the Cybersecurity and Infrastructure Security Agency within 90 days after CISA publishes the new Logging Reference Architecture, or LRA.

OMB said the plan must describe the operational steps agencies will take to deploy and maintain CEM and THIRF capabilities. Agencies also must outline actions required to meet minimum logging baseline requirements, describe additional logging activities tied to mission needs and threat environments, and explain how they will address agency-specific risk profiles.

According to OMB, agencies should align implementation plans with guidance in the LRA and periodically update the plans as needed.

What Are the Base Requirements for the Logging Reference Architecture?

OMB said CISA, in coordination with OMB and the Chief Information Security Officer Council, must publish the LRA within 90 days.

The guidance must address several baseline requirements, including:

  • Prioritization guidance for CEM and THIRF activities
  • Alignment with CISA’s Zero Trust Maturity Model
  • Options for centralized or hybrid log management architectures
  • Protections against the collection or exposure of sensitive data
  • Logging guidance for IoT and operational technology systems
  • Use of artificial intelligence technologies to enhance logging capabilities
  • Self-assessment guidance for agencies evaluating logging maturity
  • Recommendations for data retention practices beyond minimum requirements
  • Annual reassessment of the architecture to address emerging technologies and threats

What Are the Agency Implementation Deadlines?

OMB established phased implementation deadlines associated with the release of the LRA.

Under the schedule, agencies must:

  • Complete an initial Agency Logging Plan within 90 days of the architecture’s release
  • Achieve Basic Level 1 maturity within 120 days
  • Achieve Intermediate Level 2 maturity within 180 days
  • Achieve Advanced Level 3 maturity within 320 days

The memorandum also establishes ongoing update requirements whenever CISA revises the LRA.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19

Recommended For You

Jay Clayton’s DNI Nomination Advances After Senate Panel Vote

by Miles Jamison
July 22, 2026
Jay Clayton. Jay Clayton's nomination as director of ODNI cleared the Senate Intelligence Committee in a 9-8 vote.

The Senate Intelligence Committee has advanced Jay Clayton’s nomination to lead the Office of the Director of National IntelligenceThe 9-8 vote clears the way for the full Senate...

Read moreDetails

White House OSTP Report Offers Recommendations to Revitalize R&D Enterprise

by Jane Edwards
July 22, 2026
Michael Kratsios. The OSTP director has released a report outlining recommendations to renew the federal R&D enterprise.

OSTP Director Michael Kratsios has published a report on revitalizing federal R&DThe White House has outlined nine R&D priorities for FY 2028 budget planningThe 2026 FedCiv Summit will...

Read moreDetails

FCC Extends Drone Exceptions, Seeks Comment on Foreign Military-Grade Drone Ban

by Jane Edwards
July 22, 2026
Drones. FCC has extended exceptions to its Covered List ban on foreign-produced drones and drone components.

FCC has extended two Covered List exceptions for foreign-produced drones through January 2028FCC seeks comment on banning foreign-made military-grade drones for non-government useExplore AI and other modernization priorities...

Read moreDetails

US Navy’s Robotic Satellite Mechanic Payload Launches Aboard SpaceLogistics Spacecraft

by Jamie Bennet
July 22, 2026
Rocket launch. The NRL's Robotic Servicing of Geosynchronous Satellites payload has been launched into orbit.

The Naval Research Laboratory's Robotic Servicing of Geosynchronous Satellites payload has been launched into orbitThe payload was installed on SpaceLogistics' Mission Robotic Vehicle and carried by a SpaceX...

Read moreDetails

Argonne Seeks Industry Input on National AI Supercomputing Center

by Kristen Smith
July 22, 2026
Argonne logo. Argonne is seeking input from industry and academia on the development of a national AI supercomputing center.

Argonne wants to build an AI supercomputing facility running 100,000 GPUs,NVIDIA agreed to be an anchor partner supplying GPUs, with Argonne open to more partnersFeedback is due Aug....

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!