Operating model
Start with the questions an investigation must answer.
A logging program should make it possible to reconstruct meaningful events: which identity authenticated, from what device or network location, what resource was accessed, what privilege was used, what changed, what data moved, which control made the decision, and what happened next. Collecting events that cannot be tied to an owner, timestamp, asset, or action creates storage cost without equivalent investigative value.
Define logging requirements by service and attack path. Identity systems need authentication, enrollment, recovery, role, token, and privileged events. Network infrastructure needs configuration, authentication, routing, policy, VPN, DNS, DHCP, and boundary telemetry where supported. Endpoints need process, security-control, identity, and relevant operating-system events. Cloud and SaaS services need administrative, authentication, API, data-access, sharing, and configuration events appropriate to the service.
NIST CSF 2.0's Detect outcomes emphasize monitoring assets for potentially adverse events and analyzing those events to characterize possible incidents. The practical implication is that collection and analysis belong in the same operating model. A source that is never reviewed or correlated is not providing the same risk reduction as a source tied to a detection or investigation use case.