While easily compiling records and logs for compliance purposes is helpful, it doesn’t do your company much good after a breach if these logs can’t be used to investigate the attack. NIST requires that audit trails include enough information to determine what events occurred and who or what caused them. When you face a data breach, your records should be able to tell you the type of event that caused the breach, when the event occurred, the applications or commands used, and any user ID associated.