Skip to content
ControlVerdict
AU.L2-3.3.5addresses
AU.L2-3.3.5Audit Correlation
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
  • [a]

    audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined; and
  • [b]

    defined audit record review, analysis, and reporting processes are correlated.

View full control

One investigation timeline across identity, endpoint, network, and file-server events

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Audit Correlation objectives: the review, analysis, and reporting processes are defined, and those processes are correlated across sources rather than run independently.

Defined processes [a]. Three tiers are written down. Continuous: correlation searches run on a schedule and raise notable events. Daily: the analyst triages the notable queue with a documented decision (escalate, tune, or close with reason). Weekly: a trend review looks at what was tuned and whether the tuning hid something. Each tier names its owner, its input, and its output artifact.

Correlation in practice [b]. Events are normalized so the same user, host, and address fields carry the same names regardless of source. Correlation searches join across sources rather than alerting on one signal — for example, a privileged role activation with no matching change ticket and an unusual source address; or an endpoint detection followed within 15 minutes by unusual read volume on an enclave file share. Every notable event opens with an entity-scoped timeline that pulls all four sources for that user and host over the surrounding window.

Handoff to response. A notable event that escalates becomes a case, and the case carries the correlated timeline as its first artifact, so the incident process starts with evidence instead of a search box.

Maintenance. Monthly review of correlation search performance (false positives, misses found later). Quarterly purple-team exercise: a benign but detectable action is performed and the correlation must produce the timeline. Field normalization is re-validated after any source schema change.

Accepted gap. One SaaS app timestamps only to the minute, which limits ordering precision inside a one-minute window. Analysts are told to treat its ordering as approximate; sequence-critical conclusions rely on the sources with sub-second timestamps.

What the evidence looks like

  • Written three-tier review, analysis, and reporting process with owners
  • Correlation search definitions showing multi-source joins
  • Field normalization mapping across the four source types
  • A closed case with its correlated timeline attached
  • Quarterly purple-team exercise record and the resulting tuning

Environment

~700 employees with 80 in the enclave. Identity, endpoint detection, firewall, and file-server audit events all index into a single analytics platform.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.