Biden Administration Executive Order Reinforces Log Standardization is Key to Security

In May 2021, the Biden Administration issued its much-anticipated Executive Order aimed at improving the cyber posture of the country. The fact sheet accompanying its release appropriately noted that “[r]ecent cybersecurity incidents such as SolarWinds, Microsoft Exchange, and the Colonial Pipeline incident are a sobering reminder that U.S. public and private sector entities increasingly face sophisticated malicious cyber activity from both nation-state actors and cyber criminals.” Since the order’s release in May, we have not seen any decrease in the sophistication and frequency of incidents.

As we approach the end of summer, which coincides with roughly 90 days post-order release, many of the order’s requirements have already been implemented or are in the early stages of implementation. However, section 8 of the order has yet to be implemented. While this section is formally titled “Improving the Federal Government’s Investigative and Remediation Capabilities”, the main objective is to establish system log data standardization across the federal government.

After explicitly noting the importance of collecting and storing this data, the order goes on to give two key directions:

First, the Department of Homeland Security (DHS), working with the Department of Justice (DoJ), was to submit its initial recommendations regarding “requirements for logging events and retaining other relevant data within an agency’s systems and networks. Such recommendations shall include the types of logs to be maintained, the time periods to retain the logs and other relevant data, the time periods for agencies to enable recommended logging and security requirements, and how to protect logs” to the Office of Managment and Budget (OMB) by the end of May.

Second, OMB is to “formulate policies for agencies to establish requirements for logging, log retention, and log management, which shall ensure centralized access and visibility for the highest level security operations center of each agency” within 90 days of receipt of the initial recommendations from DHS. Accordingly, we should have a better understanding of the federal government’s implementation of Section 8 near the end of August with the release of the formal OMB policy.

While OMB is drafting this policy,there are perhaps two key elements around data that should be considered:

Data handling specifications on:

And, data governance specifications on:

By addressing specific frameworks such as the above, the forthcoming OMB policy should push the federal government forward in achieving the order’s goal of improving investigative and remediation capabilities. Implementing each of the order’s sections will require a sustained funding mechanism. Given the tremendous importance that has been placed on securing federal information systems, and the growing cyber threat, the administration must put forth a clear plan and funding mechanism that Congress should formally support.

Click here to learn more about Splunk and how we can help.

Related Articles

How Splunk is Helping Shape the Future of Higher Education IT by Tackling EDUCAUSE 2026 Top Issues
Industries
3 Minute Read

How Splunk is Helping Shape the Future of Higher Education IT by Tackling EDUCAUSE 2026 Top Issues

Dive into how Splunk aligns with key priorities highlighted at EDUCAUSE 2025.
Enhancing Government Resilience: How AI and Automation Empower Public Sector Missions
Industries
3 Minute Read

Enhancing Government Resilience: How AI and Automation Empower Public Sector Missions

Splunk helps government agencies boost security and efficiency with powerful, mission-ready AI and automation.
Solving Manual Mayhem in Telecom with Agentic AI
Industries
3 Minute Read

Solving Manual Mayhem in Telecom with Agentic AI

Agentic AI cuts downtime, improves security, and boosts customer experience, and with unified data from Splunk and Cisco, teams can build more resilient operations.
Upgrading to Splunk Enterprise 10.0 and Splunk Cloud Platform 10.0: Key Resources for Public Sector Customers
Industries
2 Minute Read

Upgrading to Splunk Enterprise 10.0 and Splunk Cloud Platform 10.0: Key Resources for Public Sector Customers

Splunk Enterprise 10.0 and Splunk Cloud Platform 10.0 deliver the most secure, stable, and modernized platform for a digitally resilient and compliance-ready future.
Building the Next Generation of Defenders: From the Classroom to the SOC of the Future
Industries
3 Minute Read

Building the Next Generation of Defenders: From the Classroom to the SOC of the Future

Resilience in the AI era doesn’t just happen – it's built one student, one SOC, and one organisation at a time.
Analytics That Work: 3 Approaches for the Future of Contact Centers
Industries
3 Minute Read

Analytics That Work: 3 Approaches for the Future of Contact Centers

Splunker Khalid Ali explains how unified, real-time intelligence connects data, empowers agents, and builds lasting customer loyalty.
Observability + Security: Real-Time Digital Resilience for SLED
Industries
1 Minute Read

Observability + Security: Real-Time Digital Resilience for SLED

Cisco and Splunk are helping public sector organizations build digital resilience.
Digital Resilience for State and Local Governments (Part Two)
Industries
3 Minute Read

Digital Resilience for State and Local Governments (Part Two)

Discover how collaboration—powered by shared data platforms like Splunk—can enhance incident response and overall digital resilience.
Reflections from SIBOS 2025: How will advances in technology (and especially AI) change the financial services industry over the next 5 years?
Industries
2 Minute Read

Reflections from SIBOS 2025: How will advances in technology (and especially AI) change the financial services industry over the next 5 years?

Discover key insights from SIBOS 2025 on how AI, collaboration, and data will reshape financial services over the next 5 years—prepare for rapid change and exciting opportunities ahead.