CISA logging guide reverses keep-everything mandate
Agencies drowning in log storage costs since 2021 now have explicit permission to discard data, as long as what remains is searchable and sufficient for threat hunting and incident response.
TL;DR
CISA released its Logging Reference Architecture last week, providing implementation guidance for OMB Memorandum M-26-14, which rescinded the 2021 M-21-31 logging directive. Agencies must submit logging plans to OMB and CISA by November 18. Where the 2021 mandate demanded retention of vast quantities of logging data after SolarWinds, the new architecture explicitly permits agencies to balance cost and performance against retention, as long as critical evidence remains available for threat hunting, investigation, and forensics. CISA Acting Executive Assistant Director Chris Butera said the guide steers agencies "away from fragmented practices" toward a mature enterprise capability.
The Office of Management and Budget said it plainly in May: the 2021 post-SolarWinds mandate to retain vast quantities of logging data "proved neither operationally feasible nor cost-effective for most agencies." Last week, CISA translated that admission into architecture.
M-21-31 built a flood; M-26-14 builds a filter
The Logging Reference Architecture, released August 20, converts OMB Memorandum M-26-14 into operational guidance. The May memo rescinded M-21-31, the 2021 directive that drove agencies to log everything they could after it became clear several agencies lacked the records needed to investigate the SolarWinds breach.
The problem became apparent quickly. Log storage costs ballooned. Security teams drowned in telemetry they couldn't search effectively. The volume obscured the signal.
CISA's new guide addresses this directly. Agencies should adopt retention strategies that "balance cost, performance, and operational needs while ensuring critical evidence remains available for investigations and digital forensics." The document then delivers the line that agency CISOs have been waiting for: "keeping all telemetry in high cost, long-term operational storage is often unnecessary and unsustainable."
The permission slip
This isn't a retreat from logging. It's a recalibration around two specific capabilities: Continuous Event Monitoring and Threat Hunting, Investigation, Response and Forensics. The architecture provides operational checklists organized around security outcomes rather than raw data volume.
"Retention alone is not enough if the right data cannot be searched within the time window required for monitoring, threat hunting, and routine investigation," the guide states. The corollary is unspoken but clear: searchable data retained for the right window beats comprehensive data nobody can query.
The November 18 deadline and the enforcement question
Agencies must submit their logging plans to OMB and CISA by November 18. Those plans need to document baseline and above-baseline logging decisions, source coverage, dataflow, retention, integrity protections, and access controls.
What the architecture doesn't address is enforcement. Neither the OMB memo nor the LRA specifies what CISA will do if an agency's plan is inadequate or late. For CISOs who've built logging programs under M-21-31, the immediate task is justifying what they intend to stop collecting, and proving the investigative capability survives the cut.
Published ·Deep Fathom