- CISA has published new guidance to standardize federal logging and visibility practices
- The guidance translates M-26-14 logging requirements into architecture and design decisions
- The 2026 Homeland Security Summit will explore AI, edge capabilities and more
The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency has released the Logging Reference Architecture, or LRA, an outcome-driven guidance designed to help federal civilian executive branch agencies develop logging, visibility and operational standards in an agency logging plan in compliance with the Office of Management and Budget’s Memorandum M-26-14.

As federal agencies work to strengthen logging and network visibility across their systems, the Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 10 will bring together government and industry leaders to discuss artificial intelligence, coordination for counter-UAS operations, federated data and identity fabric, edge capabilities and more. Book your spot now to join the conversation shaping the future of homeland security technology.
CISA said Thursday it developed the guide in coordination with OMB and the Chief Information Security Officers Council.
How Does the LRA Support Agency Cybersecurity?
The guidance is designed to help agencies build continuous event monitoring capabilities that support real-time network visibility. It also addresses threat hunting, incident response and digital forensics as interconnected operational functions rather than standalone tools. Agencies are expected to use the guidance to update their enterprise logging strategies and inform the development of an agency logging plan.
CISA has stated that agencies must submit their agency logging plan to OMB and CISA by Nov. 18. CISA has made available an M-26-14 Agency Logging Plan Template to provide agencies with a structured format for that submission.
Chris Butera, acting executive assistant director for cybersecurity at CISA, said effective cyber defense depends on the visibility that strong logging practices provide.
“Cyber defense begins with insight. Robust logs provide the critical visibility needed to counter daily threats targeting federal systems. CISA is enhancing agency logging strategies to ensure security teams can rapidly detect and respond to cyber incidents,” Butera stated. “The Logging Reference Architecture guides agencies away from fragmented practices, establishing a mature enterprise capability that maximizes the operational value of their data.”
What Is the Scope of the LRA?
The LRA addresses logging coverage, fidelity and architectural decisions across identity, endpoint, network, application, cloud, Internet of Things and operational technology environments. It covers how agencies should collect, transport, normalize, store, retain, access, protect and validate telemetry across their logging infrastructure.
The guidance includes operational checklists to help agencies design their logging architecture, achieve baseline logging fidelity and confirm that their plans are operationally ready. It also addresses how agencies may incorporate AI into logging processes while maintaining required governance and oversight. Although developed for federal agencies, CISA has encouraged critical infrastructure entities and state, local, territorial and tribal governments to use the guidance to benchmark their own logging practices.
How Does the LRA Fit Into CISA’s Risk-Based Security Push?
The LRA’s release comes as CISA continues shifting federal cybersecurity requirements toward risk-based, outcome-driven standards. The agency has directed federal civilian agencies to remediate vulnerabilities according to timelines based on exposure and exploitation risk rather than applying uniform deadlines to all flaws, building on an earlier mandate requiring agencies to inventory and remove unsupported edge devices from their networks.
These moves align with priorities that National Cyber Director Sean Cairncross and Nick Andersen, acting director of CISA, outlined earlier this year, when the two previewed upcoming cyber strategy and CIRCIA updates focused on securing and modernizing federal systems. CISA has also applied similar risk-based resilience concepts outside the federal government through CI Fortify, an initiative encouraging critical infrastructure operators to isolate and recover systems during cyberattacks.




