This objective ensures that the types of reportable security incidents—as identified in IR.L2-3.6.2[a]—are formally documented in your organization’s policies and procedures. The goal is to validate that users and response teams have clear written guidance on what qualifies as a reportable incident.