The asset owner shall have policies and procedures about the information contained in IACS security-related audit and event log entries to support non-repudiation and time-correlated analysis of events.