When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.