Incident Response & Operations

Activity Log Tamper-Evident · Timestamped · All Modules

The Activity Log captures every action taken within 1TEN. who changed what, when, and in which module. It creates the continuous operational record that proves your compliance program was actively maintained over time, not assembled in the weeks before an assessment.

AU.L2 3.3.1 and 3.3.2 satisfied
Append-only Cannot be modified
All modules Actions captured
The problem this solves
One of the most consistent patterns assessors look for is whether a compliance program was operating continuously or assembled just before the assessment. A platform with six months of timestamped activity. requirements assessments updated, evidence uploaded, POA&M items progressed, training completions logged. tells a fundamentally different story than one where everything was entered in a two-week window. The Activity Log creates that history automatically, as a byproduct of normal platform use.

What Gets Logged

Every user action across every module is written to the Activity Log automatically. no configuration required. Requirements assessments, status changes, evidence uploads, POA&M updates, SSP exports, policy generations, training completions, visitor sign-ins, maintenance records, configuration changes, and user account modifications all produce log entries. Each entry captures the user, the action, the affected record, and the precise timestamp.

The log is not limited to compliance-specific actions. System access events. logins, logouts, failed authentication attempts. are also captured. This means the Activity Log serves dual purpose: it satisfies AU domain requirements for audit trail creation and retention, and it provides the access accountability record that supports AC and IA domain controls.

Dashboard Requirements Reports Assets Settings

Activity Log

Audit trail of all platform activity for Demo Defense Contractors Inc.

100
Total Events
21
Auth Login
21
SSP Statement Saved
17
Automation Run
12
CUI Access
Activity History 100 events
Date / TimeUserActionEntityDetailsIP
Jun 23, 2026
7:36 PM
DADemo Admin Report Accessed Organization #1 Activity log report accessed 71.43.200.179
Jun 23, 2026
7:31 PM
DADemo Admin Auth Login User #1 User logged in 71.43.200.179
Jun 23, 2026
6:22 PM
CCCristen Causey Training Completed Training Course #5 Completed: Media Protection 35.145.234.146
Jun 23, 2026
12:14 PM
DADemo Admin SSP Statement Saved Requirement #21 SSP statement saved for AC.L2-3.1.21 71.43.200.179
Jun 19, 2026
5:38 PM
DPDon Petsche Policy Generated Policy #2 Policy generated: Security Awareness and Training Policy 35.145.61.28
Jun 19, 2026
5:17 PM
DPDon Petsche SSP Statement Saved Requirement #44 SSP statement saved for IA.L2-3.5.1 35.145.61.28
Jun 18, 2026
2:16 PM
DADemo Admin User Role Changed User #5 Admin updated profile for user_id=5 71.43.200.179
Jun 15, 2026
2:48 PM
DADemo Admin User Created User #6 User created: Cristen Causey (admin) 71.43.200.179
Jun 12, 2026
2:39 PM
DADemo Admin Approval Requested POA&M #1 POA&M closure submitted: AC.L2-3.1.20 71.43.200.179
Jun 8, 2026
7:10 PM
DADemo Admin User Created User #5 User created: Ken Angell (admin) 71.43.200.179
Showing 10 of 100 events — narrow filters for more

Tamper-Evidence and Log Integrity

The Activity Log is append-only. Platform users cannot edit, delete, or modify log entries. including administrators. This architectural choice is deliberate: it ensures that the record of what was done and when is trustworthy. An assessor reviewing the log can be confident that the timestamps reflect actual activity rather than retroactive documentation.

AU.L2-3.3.1 requires that audit logs be created and retained to enable monitoring and investigation. AU.L2-3.3.2 requires that individual user actions be traceable to those users. The Activity Log satisfies both requirements as a built-in function of the platform. no separate SIEM, no external log aggregation, no additional configuration needed.

What You See Inside

  • *Timestamped entry for every platform action across all 23 modules. automatic, no configuration required
  • *User attribution on every entry. actions are traceable to the named account that performed them
  • *Action type and affected record. what changed and which specific record was modified
  • *System access events. logins, logouts, and failed authentication attempts
  • *Append-only architecture. no user or administrator can edit or delete log entries
  • *Filterable by user, module, date range, or action type. locate specific events without scrolling through the full log
  • *Exportable log for assessor review. produce a filtered or complete log export in the format assessors request
  • *Retention on the 1TEN appliance. logs remain on-premises and are not transmitted to external systems

Actions Logged by Module

Module Actions Captured
Requirements BrowserStatus changes, implementation note edits, responsible party assignments, objective updates
Evidence ManagerFile uploads, objective linkages, description edits, file removals
POA&M TrackerItem creation, milestone updates, status changes, closure events
Policy GeneratorPolicy generation events, approval workflow actions, version creation
SSP ExportExport events with version stamp and exporting user
TrainingCourse assignments, completion events, certificate generation
Risk RegisterRisk entry creation, score updates, mitigation status changes, acceptance events
Asset InventoryAsset additions, field changes, boundary status updates, removals
Visitor Log & KioskVisitor sign-ins and sign-outs with escort and access area
Maintenance LogMaintenance record creation, completion logging, vendor access events
User ManagementAccount creation, role changes, password resets, account deactivation
All modulesSystem logins, logouts, and failed authentication attempts

What this replaces

Practices Satisfied

Practice IDDescription
AU.L2-3.3.1 Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
AU.L2-3.3.2 Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.

Related Modules

Prepare for assessment.

1TEN structures your compliance posture across all 14 CMMC domains and produces the evidence package your C3PAO will request.

Request a Demo