The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance, the Logging Reference Architecture (LRA), to help federal agencies improve their logging strategies. While primarily intended for federal civilian agencies to meet the requirements of OMB Memorandum M-26-14, CISA explicitly encourages critical infrastructure operators and other government organizations to adopt the LRA as a benchmark for their own logging and monitoring plans. The guidance, published in August 2026, emphasizes the practical usability of logs for detecting attacks and reconstructing incidents.
The LRA framework is structured around two key operational objectives: Continuous Event Monitoring (CEM) for near-real-time detection and response, and Threat Hunting, Investigation, Response, and Forensics (THIRF) for post-compromise analysis. CISA stresses that simply collecting logs is insufficient; the data must be timely, complete, reliable, and detailed enough to be useful during an actual incident. The LRA includes appendices that function as assessment tools, allowing organizations to evaluate the architectural soundness and practical effectiveness of their logging plans.
A significant aspect of the LRA is its guidance on log storage, which directly impacts cost and accessibility. It differentiates between data that needs to be immediately searchable for monitoring and hunting, data that can be moved to cheaper tiers while remaining retrievable for reconstruction, and data requiring immutable, evidentiary handling. The federal baseline suggests keeping data actively searchable for six months and retrievable for one year. The document cautions against making the Security Information and Event Management (SIEM) system the sole system of record, noting that ingesting all data into a single analytics platform can become costly and lead to data fidelity issues. Instead, it advocates for source-specific collection feeding into shared downstream processing.
The LRA also highlights the importance of treating logging infrastructure as a security-critical capability, as its compromise could blind detection, corrupt evidence, or undermine incident response. While acknowledging the benefits of centralized log storage for consistency and visibility, the guidance warns against designs that introduce delays, strip context, or create fragile chokepoints, suggesting that a more federated design with strong governance might be superior in such cases.
Regarding the use of artificial intelligence (AI) and machine learning (ML) in security operations, the LRA provides important guardrails. It stipulates that AI outputs should be considered derived data, not authoritative event records. Any actions with significant operational, legal, or privacy implications should remain subject to human review. The guidance advises agencies to maintain the relationship between original records and derived outputs, and to record sufficient metadata to support review, reproduction, and challenges of AI-generated results.
Federal agencies subject to OMB Memorandum M-26-14 are required to submit an Agency Logging Plan to the Office of Management and Budget and CISA within 90 days of the LRA's publication. This plan must detail how the agency will meet baseline requirements and identify areas where it intends to log beyond them. Agencies will then progress through a maturity model, aiming to reach an "Advanced" level within 320 days. CISA has committed to reviewing and updating the LRA at least annually to adapt to evolving threats and technologies.






