to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

3.3.9Restrict who manages logging in Rev. 3

Withdrawn and incorporated elsewhere: 03.03.08 Protection of Audit Information.

Status as of 2026-09-08

Rev. 2 is what a contract requires today. DFARS 252.204-7012 and the CMMC rule at 32 CFR 170 point at NIST SP 800-171 Rev. 2, and a standing DoD class deviation keeps it there. NIST has published Rev. 3, but publishing a revision does not change an obligation. A move to Rev. 3 would arrive through the Department's reform process and formal rulemaking, a change to that deviation or an amendment to the rule, not through publication. The Department has published its organization-defined parameter values for Rev. 3 in preparation; that is groundwork, not adoption.

Side by side

Rev. 2 · in force 3.3.9 Audit Management

Limit management of audit logging functionality to a subset of privileged users.

Assessment objectives · 800-171A

  1. [a] a subset of privileged users granted access to manage audit logging functionality is defined
  2. [b] management of audit logging functionality is limited to the defined subset of privileged users

Rev. 3 · not adopted 03.03.08 Protection of Audit Information

a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

b. Authorize access to management of audit logging functionality to only a subset of privileged users or roles.

Determination statements · 800-171A Rev. 3

  1. 03.03.08.a[01] audit information is protected from unauthorized access, modification, and deletion.
  2. 03.03.08.a[02] audit logging tools are protected from unauthorized access, modification, and deletion.
  3. 03.03.08.b access to management of audit logging functionality is authorized to only a subset of privileged users or roles.

Draws on Rev. 2 3.3.8, 3.3.9.

Left: NIST SP 800-171 Rev. 2 and 800-171A, verbatim. Right: NIST SP 800-171 Rev. 3 and 800-171A Rev. 3, verbatim, with organization-defined blanks highlighted.

Word by word

The Rev. 2 requirement compared with its Rev. 3 successor. A mechanical comparison of the two verbatim texts, not an interpretation.

removed in Rev. 3 added in Rev. 3

Rev. 2 3.3.9 → Rev. 3 03.03.08 Protection of Audit Information

Limit Protect audit information and audit logging tools from unauthorized access, modification, and deletion. Authorize access to management of audit logging functionality to only a subset of privileged users or roles.

11 words kept, 1 removed, 19 added. Rev. 3 statement labels omitted for the comparison.

What NIST says changed

Rev. 3 withdraws this requirement as a separate item and folds it into another requirement. NIST's note: Incorporated into 03.03.08.

NIST's Rev. 3 discussion for 03.03.08

Audit information includes the information needed to successfully audit system activity, such as audit records, audit log settings, audit reports, and personally identifiable information. Audit logging tools are programs and devices used to conduct audit and logging activities. The protection of audit information focuses on technical protection and limits the ability to access and execute audit logging tools to authorized individuals. The physical protection of audit information is addressed by media and physical protection requirements. Individuals or roles with privileged access to a system and who are also the subject of an audit by that system may affect the reliability of the audit information by inhibiting audit activities or modifying audit records. Requiring privileged access to be further defined between audit-related privileges and other privileges limits the number of users or roles with audit-related privileges.

What this means for you now

Nothing changes in what you are assessed against until a class deviation or a published rule adopts Rev. 3. Keep meeting 3.3.9 as written in Rev. 2.

Bedrock CMMC shows this same comparison against your own package, with your current status on the Rev. 2 side, so the day adoption lands the migration is a review, not a rewrite.

Back to the Rev. 2 vs Rev. 3 overview

Where this page's facts come from
Rev. 2 text and objectives
bedrock-cmmc-api@89b8e8e:migrations/004_reference_requirements.sql#Requirement.basicRequirement@rev2; bedrock-cmmc-api@89b8e8e:migrations/005_reference_objectives.sql#AssessmentObjective.description@rev2
Mapping and change class
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/r2_r3_transition_map.json#r2_to_r3
Rev. 3 03.03.08
bedrock-cmmc-api@89b8e8e:docs/reference/nist-800-171-rev3/normalized/rev3.json#requirements[]