to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.3.8Protect the logs themselves in Rev. 3

Reworded: 03.03.08 Protection of Audit Information.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.3.8 Audit Protection

Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

Assessment objectives · 800-171A

  1. [a] audit information is protected from unauthorized access
  2. [b] audit information is protected from unauthorized modification
  3. [c] audit information is protected from unauthorized deletion
  4. [d] audit logging tools are protected from unauthorized access
  5. [e] audit logging tools are protected from unauthorized modification
  6. [f] audit logging tools are protected from unauthorized deletion

Rev. 3 · not adopted 03.03.08 Protection of Audit Information

a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

b. Authorize access to management of audit logging functionality to only a subset of privileged users or roles.

Determination statements · 800-171A Rev. 3

  1. 03.03.08.a[01] audit information is protected from unauthorized access, modification, and deletion.
  2. 03.03.08.a[02] audit logging tools are protected from unauthorized access, modification, and deletion.
  3. 03.03.08.b access to management of audit logging functionality is authorized to only a subset of privileged users or roles.

Draws on Rev. 2 3.3.8, 3.3.9.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

Word by word

The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.

removed in Rev. 3 added in Rev. 3

Rev. 2 3.3.8 → Rev. 3 03.03.08 Protection of Audit Information

Protect audit information and audit logging tools from unauthorized access, modification, and deletion. Authorize access to management of audit logging functionality to only a subset of privileged users or roles.

13 words kept, 0 removed, 17 added. Rev. 3 statement labels omitted for the comparison.

What NIST says changed

  • New security requirement title
  • Includes withdrawn requirement: 03.03.09

NIST, SP 800-171 Rev. 2 to Rev. 3 change analysis, class “Significant change”. At adoption, Bedrock files this under “Rework”.

NIST's Rev. 3 discussion for 03.03.08

Audit information includes the information needed to successfully audit system activity, such as audit records, audit log settings, audit reports, and personally identifiable information. Audit logging tools are programs and devices used to conduct audit and logging activities. The protection of audit information focuses on technical protection and limits the ability to access and execute audit logging tools to authorized individuals. The physical protection of audit information is addressed by media and physical protection requirements. Individuals or roles with privileged access to a system and who are also the subject of an audit by that system may affect the reliability of the audit information by inhibiting audit activities or modifying audit records. Requiring privileged access to be further defined between audit-related privileges and other privileges limits the number of users or roles with audit-related privileges.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.3.8 as written in Rev. 2.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Rev. 3 03.03.08
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]