Cybatar Security Hub · Governance · Risk Management · Threat Resilience · Compliance & Audit
Unified enterprise security operations for modern organisations
Detection Engineering / Log-source coverage
Detection engineering guide

Detection Log-Source Coverage

How should a security team measure log-source coverage for detection?

Direct answer

Measure coverage as a chain, not a source count: required source, accountable owner, connection state, expected event categories, recent ingestion, usable normalized fields, time quality, retention/access expectations, dependent detections, and known gaps. A source listed in an inventory is not evidence that useful telemetry is arriving or that a detection can use it.

External reference

National Institute of Standards and Technology (NIST) — SP 800-137 — Information Security Continuous Monitoring

Final NIST guidance on continuous monitoring strategy, visibility into assets, threats, vulnerabilities and the effectiveness of deployed security controls.

https://csrc.nist.gov/pubs/sp/800/137/final

Detection engineering workflow

1

Define required sources

Tie each important detection objective to the systems, identities, network paths, cloud services or applications that can provide relevant telemetry.

2

Verify arrival and usability

Check recent ingestion, parser/normalization success, source identifiers, timestamps and fields needed for analysis.

3

Link sources to detections

Record which detections depend on each source and which sources have no active analytic use.

4

Track gaps explicitly

Record unavailable sources, partial field coverage, retention limits, blind spots and owners for remediation.

5

Review continuously

Reassess after architecture, identity, cloud, application or logging changes rather than treating onboarding as permanent proof of coverage.

Relevant Cybatar operating surfaces

Claim boundary

A configured source does not prove complete telemetry, correct retention, time synchronisation, field quality or detection effectiveness. Coverage must be verified against the organisation’s actual environment.

These pages are Cybatar-authored detection-engineering guidance. External taxonomies and standards are referenced for context; the mappings are not official MITRE, NIST or vendor validations, certifications, endorsements or statements that a particular deployment will detect a technique.

Evidence and methodology