AU.L2-3.3.5Audit Correlation
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
[a]
audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined; and[b]
defined audit record review, analysis, and reporting processes are correlated.
One investigation timeline across identity, endpoint, network, and file-server events
Implementation
AO coverage. Addresses both Audit Correlation objectives: the review, analysis, and reporting processes are defined, and those processes are correlated across sources rather than run independently.
Defined processes [a]. Three tiers are written down. Continuous: correlation searches run on a schedule and raise notable events. Daily: the analyst triages the notable queue with a documented decision (escalate, tune, or close with reason). Weekly: a trend review looks at what was tuned and whether the tuning hid something. Each tier names its owner, its input, and its output artifact.
Correlation in practice [b]. Events are normalized so the same user, host, and address fields carry the same names regardless of source. Correlation searches join across sources rather than alerting on one signal — for example, a privileged role activation with no matching change ticket and an unusual source address; or an endpoint detection followed within 15 minutes by unusual read volume on an enclave file share. Every notable event opens with an entity-scoped timeline that pulls all four sources for that user and host over the surrounding window.
Handoff to response. A notable event that escalates becomes a case, and the case carries the correlated timeline as its first artifact, so the incident process starts with evidence instead of a search box.
Maintenance. Monthly review of correlation search performance (false positives, misses found later). Quarterly purple-team exercise: a benign but detectable action is performed and the correlation must produce the timeline. Field normalization is re-validated after any source schema change.
Accepted gap. One SaaS app timestamps only to the minute, which limits ordering precision inside a one-minute window. Analysts are told to treat its ordering as approximate; sequence-critical conclusions rely on the sources with sub-second timestamps.
What the evidence looks like
- Written three-tier review, analysis, and reporting process with owners
- Correlation search definitions showing multi-source joins
- Field normalization mapping across the four source types
- A closed case with its correlated timeline attached
- Quarterly purple-team exercise record and the resulting tuning
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.