Create, protect, and retain system audit logs — 9 requirements covering 17 total SPRS points.
The Audit and Accountability domain requires organizations to create, protect, and regularly review audit logs for systems that process CUI. These logs are critical for detecting security incidents, investigating events, and demonstrating that security controls are operating. You can't detect what you don't log. Audit logs are the forensic record of what happened in your systems — who accessed what, when, from where, and what changed. Without robust audit logging and regular review, security incidents go undetected and evidence of compromise is lost.
Each requirement maps directly to NIST SP 800-171 Rev 2. SPRS point values reflect the DoD scoring weight — 5-point requirements are the most critical and cannot be deferred to a POA&M.
| Requirement | Description | Points | POA&M |
|---|---|---|---|
| AU.L2-3.3.1 | Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. | 5 | Conditional |
| AU.L2-3.3.2 | Ensure that the actions of individual system users can be traced to those users, so they can be held accountable for their actions. | 3 | Yes |
| AU.L2-3.3.3 | Review and update logged events. | 1 | Yes |
| AU.L2-3.3.4 | Alert in the event of an audit logging process failure. | 1 | Yes |
| AU.L2-3.3.5 | Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. | 5 | Conditional |
| AU.L2-3.3.6 | Provide audit record reduction and report generation to support on-demand analysis and reporting. | 1 | Yes |
| AU.L2-3.3.7 | Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records. | 1 | Yes |
| AU.L2-3.3.8 | Protect audit information and audit tools from unauthorized access, modification, and deletion. | 1 | Yes |
| AU.L2-3.3.9 | Limit management of audit logging to a subset of privileged users. | 1 | Yes |
Every action on the platform is recorded in a tamper-evident audit log with user attribution, timestamp, and action detail. Satisfies 3.3.1 and 3.3.2 with immutable records stored on the appliance.
The platform integrates with Wazuh and other SIEM solutions to correlate audit records across your environment. Supports 3.3.5 with centralized log correlation and automated alerting on suspicious activity.
Audit records are stored in append-only format with access restricted to designated administrators. Non-privileged users cannot modify or delete audit data, satisfying 3.3.8 and 3.3.9.
Filter, search, and export audit records on demand. Generate reports by user, time range, action type, or module. Covers 3.3.6 with built-in audit record reduction and report generation.
The appliance synchronizes with authoritative time sources and generates consistent timestamps across all audit records. Documents your NTP configuration for 3.3.7 compliance.
The platform monitors its own audit logging process and alerts administrators if logging fails or is interrupted. Satisfies 3.3.4 with automated detection and notification.
These tools are commonly used by defense contractors to satisfy AU requirements. During your C3PAO assessment, you'll document exactly which tools satisfy each control.
Assessors will verify that logging is enabled on all CUI-handling systems and that logs capture authentication events, privileged operations, and CUI access. They'll check log retention periods, ask about log review procedures, and look for evidence that logs are protected from unauthorized modification.
Without audit logs, you cannot prove that any other control is working. Audit and Accountability is the evidentiary foundation of your entire CMMC program. An assessor who cannot verify logging will question every other domain.
1TEN provides the GRC framework defense manufacturers need to track, score, and evidence their CMMC Level 2 posture.
Request a Demo