The asset owner shall have policies and procedures around utilizing interfaces commonly accepted by the industrial and security communities to access IACS security-related audit and event logs.