Cybersecurity events are documented based on the established criteria
Anything that is an event according to the criteria defined in RESPONSE-1b should be documented in a consistent manner. The organization should decide what details about events should be documented to enable, for example, (1) decisions about declaring events to be incidents, (2) collection of data for any event metrics the organization might be tracking, and (3) correlation of event information, if the organization is doing that.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RESPONSE-1a, RESPONSE-1b, RESPONSE-1c, RESPONSE-1f.