Skip to main content
Federal Logging Plans: Your Nov. 18 Submission ChecklistContinuous Monitoring
5 min readFor Government Agency Security Teams

Federal Logging Plans: Your Nov. 18 Submission Checklist

If you're drafting your agency's logging plan for the November 18 deadline, you're facing two main challenges: OMB's demand for mature enterprise logging capabilities and your budget office's concerns about storing vast amounts of data that may never be used.

CISA's Logging Reference Architecture offers a framework to balance these demands. This checklist translates that framework into actionable submission requirements. Each item is designed to be verifiable before submission.

What This Checklist Covers

Your logging plan must show how you'll achieve four security outcomes: continuous event monitoring, threat hunting, incident response, and digital forensics. This checklist structures your plan around these outcomes while addressing cost-effectiveness concerns that have hindered many M-21-31 implementations.

This isn't a controls assessment. You're designing an enterprise capability, not just checking boxes on AU-2 or AU-12.

Prerequisites

Before starting this checklist, confirm:

  • You have current retention costs per GB across your storage tiers (hot, warm, cold, archive).
  • You can identify which log sources currently feed your Security Operations Center.
  • You know your mean time to investigate for the last 90 days.
  • You have at least draft authority from your Chief Information Officer to propose changes to existing retention policies.

If you're missing any of these, pause. You can't write a defensible plan without baseline cost and performance data.

Logging Plan Checklist

1. Define your retention strategy by operational tier, not by calendar duration

Map each log source to one of three tiers based on search requirements:

  • Operational tier: logs you must search within minutes (typically 30-90 days in hot storage).
  • Investigative tier: logs you search during incident response (90 days to 1 year in warm storage).
  • Forensic tier: logs you preserve for compliance or legal hold (1+ years in cold/archive storage).

Done looks like: A matrix showing every log source, its assigned tier, the justification for that tier, and the storage cost delta compared to your current approach.

2. Justify retention periods with specific use cases, not regulatory minimums

For each log source in your operational and investigative tiers, document:

  • Which of the four security outcomes require this log.
  • The longest realistic search window for that outcome.
  • Why shorter retention would create an unacceptable gap.

Done looks like: You can answer "why 180 days?" for every retention decision with a concrete scenario, not "NIST says" or "we've always done it this way."

3. Identify logs you'll stop retaining or move to cheaper storage

CISA's architecture acknowledges that retaining everything is unsustainable. Document which logs you currently retain that provide minimal security value and either:

  • Reduce their retention period.
  • Move them to archive-only storage.
  • Stop collecting them entirely.

Done looks like: A cost savings projection showing freed capacity you can redirect to higher-value telemetry.

4. Map your logging architecture to CISA's operational checklists

CISA provides outcome-specific checklists in the reference architecture. For each security outcome, document:

  • Which checklist items you currently satisfy.
  • Which items require new log sources or integration work.
  • Your timeline to close gaps.

Done looks like: A gap analysis showing current state, target state, and remediation plan for continuous event monitoring, threat hunting, incident response, and digital forensics capabilities.

5. Specify your search performance requirements

"Retention alone is not enough if the right data cannot be searched within the time window required" is CISA telling you that 18-month retention doesn't help if queries take 6 hours to run.

For each tier, document:

  • Maximum acceptable query response time.
  • Expected query complexity (simple field match vs. multi-source correlation).
  • Concurrent analyst capacity.

Done looks like: Service-level objectives for search performance that your logging platform can demonstrably meet at your projected data volumes.

6. Document your AI integration approach

The reference architecture addresses AI in logging processes. You don't need a production AI deployment by November 18, but you must show you've considered:

  • Where AI-assisted analysis could reduce analyst workload.
  • What data quality or normalization work is required before AI tools can be effective.
  • How you'll validate AI-generated findings before acting on them.

Done looks like: A paragraph explaining either your AI roadmap or your decision to defer AI integration with specific reasoning.

7. Show how you'll measure operational value

OMB wants logging that provides "measurable security benefits." Define metrics you'll track quarterly:

  • Mean time to detect for your top threat scenarios.
  • Percentage of incidents where logs provided actionable evidence.
  • Cost per GB of retained data by tier.
  • Analyst hours saved through automation or improved search.

Done looks like: A measurement framework with baseline values (even if those baselines are "unknown, will establish in Q1") and target improvements.

Common Mistakes

Treating this as a compliance exercise. Your plan isn't a NIST 800-53 control assessment. It's an operational design document. If you're copying language from AU-family controls, you're writing the wrong thing.

Assuming "more retention" equals "better security." CISA's architecture pushes back against that assumption. If you can't articulate why you need 18 months of DHCP logs in searchable storage, you probably don't.

Ignoring the cost question. OMB explicitly called out M-21-31 implementations that were "not cost-effective." If your plan increases storage costs without showing operational benefit, expect pushback.

Submitting a vendor roadmap instead of an agency capability plan. Your logging platform matters, but the plan should focus on outcomes and architecture, not product features.

Next Steps

After you submit on November 18:

Establish your baseline metrics immediately. You committed to measuring operational value. Start collecting those metrics in December so you have trend data for your first quarterly review.

Schedule a cost review for Q2 2025. Once you've implemented your tiered retention strategy, validate actual costs against projections. Adjust tier assignments if operational patterns don't match your assumptions.

Revisit your AI integration decision in 6 months. The AI landscape for security operations is moving quickly. What's not feasible today may be practical by mid-2025.

Your November 18 submission isn't the end of this work. It's the start of treating logging as an enterprise capability you'll continuously refine, not a compliance checkbox you satisfy once and forget.

You Might Also Like