The asset owner shall have policies and procedures around the analysis of IACS securityrelated events to identify and characterize attacks, security compromises and security incidents in a timely manner.