AU Domain

Audit & Accountability CMMC Level 2

Create, protect, and retain system audit logs — 9 requirements covering 17 total SPRS points.

9 Requirements
17 SPRS Points at Risk
100% Complete Coverage

Audit & Accountability Domain Overview

The Audit and Accountability domain requires organizations to create, protect, and regularly review audit logs for systems that process CUI. These logs are critical for detecting security incidents, investigating events, and demonstrating that security controls are operating. You can't detect what you don't log. Audit logs are the forensic record of what happened in your systems — who accessed what, when, from where, and what changed. Without robust audit logging and regular review, security incidents go undetected and evidence of compromise is lost.

All 9 Audit & Accountability Requirements

Each requirement maps directly to NIST SP 800-171 Rev 2. SPRS point values reflect the DoD scoring weight — 5-point requirements are the most critical and cannot be deferred to a POA&M.

RequirementDescriptionPointsPOA&M
AU.L2-3.3.1Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.5Conditional
AU.L2-3.3.2Ensure that the actions of individual system users can be traced to those users, so they can be held accountable for their actions.3Yes
AU.L2-3.3.3Review and update logged events.1Yes
AU.L2-3.3.4Alert in the event of an audit logging process failure.1Yes
AU.L2-3.3.5Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.5Conditional
AU.L2-3.3.6Provide audit record reduction and report generation to support on-demand analysis and reporting.1Yes
AU.L2-3.3.7Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records.1Yes
AU.L2-3.3.8Protect audit information and audit tools from unauthorized access, modification, and deletion.1Yes
AU.L2-3.3.9Limit management of audit logging to a subset of privileged users.1Yes

How 1TEN Covers This Domain

Tamper-Evident Activity Log

Every action on the platform is recorded in a tamper-evident audit log with user attribution, timestamp, and action detail. Satisfies 3.3.1 and 3.3.2 with immutable records stored on the appliance.

SIEM Integration

The platform integrates with Wazuh and other SIEM solutions to correlate audit records across your environment. Supports 3.3.5 with centralized log correlation and automated alerting on suspicious activity.

Audit Log Protection

Audit records are stored in append-only format with access restricted to designated administrators. Non-privileged users cannot modify or delete audit data, satisfying 3.3.8 and 3.3.9.

Report Generation & Reduction

Filter, search, and export audit records on demand. Generate reports by user, time range, action type, or module. Covers 3.3.6 with built-in audit record reduction and report generation.

NTP Time Synchronization

The appliance synchronizes with authoritative time sources and generates consistent timestamps across all audit records. Documents your NTP configuration for 3.3.7 compliance.

Logging Failure Alerts

The platform monitors its own audit logging process and alerts administrators if logging fails or is interrupted. Satisfies 3.3.4 with automated detection and notification.

Common Tools for AU Compliance

These tools are commonly used by defense contractors to satisfy AU requirements. During your C3PAO assessment, you'll document exactly which tools satisfy each control.

What C3PAO Assessors Verify

Assessors will verify that logging is enabled on all CUI-handling systems and that logs capture authentication events, privileged operations, and CUI access. They'll check log retention periods, ask about log review procedures, and look for evidence that logs are protected from unauthorized modification.

Why This Domain Matters
Without audit logs, you cannot prove that any other control is working. Audit and Accountability is the evidentiary foundation of your entire CMMC program. An assessor who cannot verify logging will question every other domain.

Related Domains

Structure your posture.

1TEN provides the GRC framework defense manufacturers need to track, score, and evidence their CMMC Level 2 posture.

Request a Demo