to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.3.5Correlate logs across systems

Bring logs together so a pattern spanning several systems becomes visible.

The requirement, verbatim

NIST SP 800-171 Rev. 2 · 3.3.5

Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

Requirement 3.3.5, practice name in the CMMC assessment guide: Audit Correlation.

NIST's discussion

Correlating audit record review, analysis, and reporting processes helps to ensure that they do not operate independently, but rather collectively. Regarding the assessment of a given organizational system, the requirement is agnostic as to whether this correlation is applied at the system level or at the organization level across all systems.

NIST SP 800-171 Rev. 2, discussion under 3.3.5. Whitespace normalised; wording unchanged.

Assessment objectives

An assessor decides each of these separately. The requirement is met only when every objective is.

  1. [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined
  2. [b] defined audit record review, analysis, and reporting processes are integrated
  3. [c] audit record review, analysis, and reporting processes are correlated

NIST SP 800-171A, determination statements for 3.3.5.

For assessors: examine, interview, test

NIST SP 800-171A names what an assessor may examine, whom they may interview, and what they may test for this requirement. Assessors select from these lists; they are not a checklist of everything you must produce.

Examine
  • Audit and accountability policy
  • procedures addressing audit record generation
  • procedures for audit review, analysis, and reporting
  • system design documentation
  • system security plan
  • system configuration settings and associated documentation
  • system audit logs and records
  • audit record correlation reports or records
  • other relevant documents or records
Interview
  • Personnel with audit review, analysis, correlation, and reporting responsibilities
  • personnel with information security responsibilities
  • system or network administrators
Test
  • Mechanisms implementing audit correlation processes

NIST SP 800-171A, potential assessment methods and objects for 3.3.5.

Evidence

No evidence examples are published for this requirement yet. The objectives above are what an assessor checks; evidence is whatever shows each one is true in your environment, dated and kept with your system security plan.

Scoring weight

Worth 5 points. Not meeting this requirement subtracts 5 from your 110-point SPRS score. These are the requirements with the largest effect on your posture.

DoD NIST SP 800-171 Assessment Methodology v1.2.1 weighting, as carried in the Bedrock scoring table. The score starts at 110 and subtracts the weight of every requirement not met.

In Rev. 3

Rev. 2 is what your contract requires today. A standing DoD class deviation keeps Rev. 2 in force; NIST has published Rev. 3, but it is not adopted for contracts. In Rev. 3 this requirement is reworded: 03.03.05 Audit Record Review, Analysis, and Reporting. It gains organization-defined parameters.

See the Rev. 2 and Rev. 3 wording word by word, or start with the status page.

Where this page's facts come from
Requirement text
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2
Discussion
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.discussion@rev2
Practice name
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.title@rev2 (CMMC Assessment Guide practice name)
Objectives
bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Examine, interview, test
bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2 ({examineGuidance, interviewGuidance, testGuidance})
Level
bedrock-cmmc-api@89b8e8e:migrations/021_fix_level1_requirements.sql#Requirement.cmmcLevel@rev2
Weight
bedrock-cmmc-api@89b8e8e:internal/cmmc/requirement_values.go#requirementValues (DoD AM v1.2.1 / eMASS L2 template v3.8)
Rev. 3 mapping
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Plain-language title and summary
editorial/CMMC Navigator.dc.html#RAW (Foxx Cyber editorial)