Logging data from impacted assets cannot be inspected when investigating a cybersecurity event
Context and Guidance: Logging data that is collected from your assets (such as networks, systems, and applications) can serve as a key source of information to support the early detection of a cybersecurity threat.
Ensuring that logging data is available when investigating a cybersecurity event is also important. When assets are impacted, and logging data generated by those assets is unavailable, you have a limited ability to respond.
Example activities that indicate this Anti-Pattern is Present include: