Logging data is only monitored when a cybersecurity incident occurs
Context and Guidance: Logging data that is collected from your assets (such as networks, systems, and applications) can serve as a key source of information to support the early detection of a cybersecurity threat.
As a result, you should proactively monitor logging data in addition to monitoring during and after a cybersecurity incident.