ETSI EN 319 401 expects continuous monitoring/logging, detection/alarms for abnormal activity, and automated processing of audit logs with alerting for critical security events. This means manual log review without tooling is rarely defensible.
Incident response expectations include containment/eradication/recovery, communication plans, training/competence, documentation throughout detection/response, and explicit time-bound handling such as 48-hour critical vulnerability handling and 24-hour breach notification procedures for significant impact breaches.