Measure coverage as a chain, not a source count: required source, accountable owner, connection state, expected event categories, recent ingestion, usable normalized fields, time quality, retention/access expectations, dependent detections, and known gaps. A source listed in an inventory is not evidence that useful telemetry is arriving or that a detection can use it.
External reference
Final NIST guidance on continuous monitoring strategy, visibility into assets, threats, vulnerabilities and the effectiveness of deployed security controls.
https://csrc.nist.gov/pubs/sp/800/137/finalDetection engineering workflow
Define required sources
Tie each important detection objective to the systems, identities, network paths, cloud services or applications that can provide relevant telemetry.
Verify arrival and usability
Check recent ingestion, parser/normalization success, source identifiers, timestamps and fields needed for analysis.
Link sources to detections
Record which detections depend on each source and which sources have no active analytic use.
Track gaps explicitly
Record unavailable sources, partial field coverage, retention limits, blind spots and owners for remediation.
Review continuously
Reassess after architecture, identity, cloud, application or logging changes rather than treating onboarding as permanent proof of coverage.
Relevant Cybatar operating surfaces
Claim boundary
A configured source does not prove complete telemetry, correct retention, time synchronisation, field quality or detection effectiveness. Coverage must be verified against the organisation’s actual environment.
These pages are Cybatar-authored detection-engineering guidance. External taxonomies and standards are referenced for context; the mappings are not official MITRE, NIST or vendor validations, certifications, endorsements or statements that a particular deployment will detect a technique.