Methodology for Assessing the Quality of Information Security Event Logging in an Iterative Management Cycle Using the Logging Deficit Metric

DOI: 10.21293/1818-0442-2026-29-1-114-123

Download article in PDF format

JATS xml

Abstract: Relevance. The quality of information security event logging determines the completeness of subsequent normalization, correlation, and incident analysis in SIEM systems. Incomplete or structurally incorrect events reduce infrastructure observability and complicate incident response. Purpose of the study is to develop a methodology for the quantitative assessment of information security event logging quality based on the integral logging deficit indicator DL and the iterative PDCA cycle. Methods. The study uses logging profile formalization, a matrix of event logging requirements, a set of mandatory fields, logging completeness and accuracy metrics, a recurrent DL dynamics model, and an IDEF0 representation of the methodology. Novelty. A methodology is proposed that combines a logging requirements matrix, a set of mandatory fields, the integral DL-indicator, and inter-iteration accounting of newly detected and eliminated deficits in the PDCA cycle. Results. Using a Windows authentication event stream as an example, a decrease in DL from 0.30 to 0.11 over five iterations is shown, with the number of valid records increasing from 700 to 890. Practical significance. The methodology can be applied for formalized logging quality control, prioritizing corrective actions, and integrating event quality assessment into regular information security monitoring processes.

Keywords: PDCA, SIEM, security event logging quality assessment, logging completeness and accuracy, logging deficit, mathematical model, iterative methodologies, ISO 27001, NIST CSF

For citation:
Ivanov A. V., Kiselev M. A. Methodology for Assessing the Quality of Information Security Event Logging in an Iterative Management Cycle Using the Logging Deficit Metric. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2026, vol. 29, no. 1, pp. 114–123. DOI: 10.21293/1818-0442-2026-29-1-114-123

Authors and copyright holders:

  • Ivanov A. V. , Novosibirsk State Technical University (Novosibirsk, Russia)
  • Kiselev M. A. , Novosibirsk State Technical University (Novosibirsk, Russia)

  • 1. Sidak A.A., Sidak D.A. Standardization of processes for security event registration, monitoring and information security incident management. Dual Technologies, 2023, no. 3(104), pp. 58–62 (in Russ.).
  • 2. Kanev A.N. Monitoring sobytiy i obnaruzhenie intsi-dentov informatsionnoy bezopasnosti s ispol'zovaniem SIEM-sistem [Monitoring of events and detection of information secu-rity incidents using SIEM systems]. Mezhdunarodnyi studencheskii nauchnyi vestnik, 2015, no. 3-1, pp. 122–123 (in Russ.).
  • 3. IBM Security; Ponemon Institute. Cost of a Data Breach Report 2023. IBM Security, 2023. 85 pp. Available online: https://www.ibm.com/reports/data-breach (аccessed: 10 March 2025).
  • 4. Cisco Talos Incident Response. Quarterly Report: Q1 2024 Trends. Cisco Talos, 2024. Available online: https://blog.talosintelligence.com/talos-ir-q1-2024-quarterly-report (аccessed: 12 March 2025).
  • 5. International Organization for Standardization. ISO / IEC 27001:2022. Information security, cybersecurity and priva-cy protection – Information security management systems. – Requirements. Geneva, ISO, 2022, 33 p.
  • 6. Pascoe C., Quinn S., Scarfone K. The NIST Cyberse-curity Framework (CSF) 2.0. Gaithersburg, MD, National Institute of Standards and Technology, 2024, 32 p. DOI: 10.6028/NIST.CSWP.29.
  • 7. European Union Agency for Cybersecurity (ENISA). Technical Implementation Guidance on Cybersecurity Risk Management Measures. June 2025, version 1.0. Luxembourg, Publications Office of the European Union, 2025, 170 p. DOI: 10.2824/2702548.
  • 8. Kent K., Souppaya M. Guide to Computer Security Log Management. Gaithersburg, MD, National Institute of Standards and Technology, 2006, 64 p. Special Publication 800-92.
  • 9. Landauer M., Onder S., Skopik F., Wurzenberger M. Deep learning for anomaly detection in log data: A survey. Machine Learning with Applications, 2023, vol. 12, art. 100470. DOI: 10.1016/j.mlwa.2023.100470.
  • 10. Chuvakin A.A., Schmidt K.J., Phillips C. Logging and Log Management: The Authoritative Guide to Understand-ing the Concepts Surrounding Logging and Log Management. Burlington, MA, Syngress, 2013, 460 p. DOI: 10.1016/C2010-0-65241-2.
  • 11. GOST R 59548–2022. Zashchita informatsii. Regis-tratsiya sobytiy bezopasnosti. Trebovaniya k registriruemoy informatsii [Information security. Security event logging. Requirements for logged information]. Moscow, Standartin-form Publ., 2022, 70 p. (in Russ.).
  • 12. Zhemchugov A.M., Zhemchugov M.K. Tsikl PDCA Deminga. Sovremennoe razvitie [Deming’s PDCA cycle: mod-ern development]. Problemy ekonomiki i menedzhmenta, 2016, no. 2 (54), pp. 3–28 (in Russ.).
  • 13. ISACA. COBIT 2019 Framework: Governance and Management Objectives. Schaumburg, IL, Information Systems Audit and Control Association, 2018, 262 p.
  • 14. Cichonski P., Millar T., Grance T., Scarfone K. Computer Security Incident Handling Guide. Gaithersburg, MD, National Institute of Standards and Technology, 2012, 79 p. NIST Special Publication 800-61 Rev. 2. DOI: 10.6028/NIST. SP.800-61r2.
  • 15. Gujarati D.N. Basic Econometrics. 4th ed. New York, McGraw-Hill, 2003, 1002 p.
  • 16. Gardner E.S. Exponential smoothing: the state of the art. Journal of Forecasting, 1985, vol. 4, no. 1, pp. 1–28. DOI: 10.1002/for.3980040103.
  • 17. Nise N.S. Control Systems Engineering. 8th ed. Ho-boken, NJ, Wiley, 2019, 800 p.
  • 18. Makarenko S.I. Audit of Information Security – the Main Stages, Conceptual Framework, Classification of Types. Systems of Control, Communication and Security, 2018, no. 1, pp. 1–29. DOI: 10.24411/2410-9916-2018-10101 (in Russ.).
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates