The asset owner shall have policies and procedures related to the reporting, logging, analysis and response (immediate or delayed) of IACS security-related events that are detected to support security management activities.