The Cybersecurity and Infrastructure Security Agency has released a new Logging Reference Architecture intended to help federal civilian executive branch agencies meet Office of Management and Budget Memorandum M-26-14 requirements for logging, visibility, and operational standards. Developed with OMB and the Chief Information Security Officers Council, the guidance lays out an outcome-focused, risk-based approach designed to strengthen agency network monitoring.
“Cyber defense begins with insight. Robust logs provide the critical visibility needed to counter daily threats targeting federal systems. CISA is enhancing agency logging strategies to ensure security teams can rapidly detect and respond to cyber incidents,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “The Logging Reference Architecture guides agencies away from fragmented practices, establishing a mature enterprise capability that maximizes the operational value of their data.”
CISA said the architecture aligns directly to M-26-14’s objectives, helping agencies prioritize capabilities that support continuous event monitoring, threat hunting, incident response, and forensics. Agencies are expected to use the guidance to update enterprise logging strategies and inform an Agency Logging Plan, which must be submitted to OMB and CISA by November 18, 2026. CISA is also providing an Agency Logging Plan Template to standardize planning.
The document includes operational checklists to steer logging architecture design and organizational strategy, set a baseline for logging fidelity, and ensure plans are ready to deliver required security outcomes. It also addresses how agencies can integrate artificial intelligence into logging processes while maintaining governance and oversight.
Although tailored for federal use, CISA is urging critical infrastructure operators and state, local, territorial, and tribal governments to review the framework as a benchmark for their own logging and monitoring programs.




