Skip to content
ControlVerdict
AU.L2-3.3.1CMMC Level 2Level 2

System Auditing

Practice statement

Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.3.1.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(6)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified;

    1 example covers this

  2. [b]

    the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined;

    1 example covers this

  3. [c]

    audit records are created (generated);

    1 example covers this

  4. [d]

    audit records, once created, contain the defined content;

    1 example covers this

  5. [e]

    retention requirements for audit records are defined; and

    1 example covers this

  6. [f]

    audit records are retained as defined.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AU.L2-3.3.1System Auditing
    Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.
    • [a]

      audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified;
    • [b]

      the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined;
    • [c]

      audit records are created (generated);
    • [d]

      audit records, once created, contain the defined content;
    • [e]

      retention requirements for audit records are defined; and
    • [f]

      audit records are retained as defined.

    Central SIEM with required event catalog and 90-day hot retention

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. Only 2 verdicts so far.Last verdict Aug 2, 2026

    Implementation

    AO coverage. Addresses all create/retain audit-record objectives for this practice.

    Event catalog (minimum). Successful/failed authentication (IdP + local), privileged role activation, changes to security groups that gate CUI, MFA method registration/removal, endpoint malware detections from Falcon, firewall / Conditional Access policy edits, and admin configuration changes on the IdP and Sentinel itself.

    Collection. Entra audit logs stream continuously to Sentinel. Endpoints forward security telemetry via Falcon and the Azure Monitor Agent where needed. Linux jump hosts use journald → forwarder with immutable local spool if Sentinel is unreachable.

    Time. All collectors NTP-synced; Sentinel normalizes to UTC.

    Retention. Hot searchable retention ≥ 90 days for the catalog above; cold archive per contract (often 1 year). Deletion of Sentinel retention settings is itself logged and alerted.

    Maintenance. Weekly “silent source” check: each expected source must have sent events in the last 24h or a ticket opens. Quarterly review that new CUI apps were added to the catalog.

    Accepted gap. One SaaS CAD tool offers only 30 days of native audit export. A daily pull job archives those events into Sentinel; failure of the pull alerts on-call.

    What the evidence looks like

    • Event catalog mapped to systems
    • Sentinel data-connector / Falcon agent inventory
    • Retention settings screenshot/export
    • Sample queries proving each event type is present
    • Silent-source alert ticket history

    Environment

    Cloud-heavy OSC; mix of Windows endpoints and a small Linux jump tier.

    Tools

    2 ratings on this revision

    • AlignedControlVerdict Consultant@cv-consultantConsultantAug 2, 2026

      Across the finish line

      Rationale document plus collection config plus retention is a solid package for a small SIEM.

    • BorderlineControlVerdict Assessor@cv-assessorAug 2, 2026

      Across the finish line

      Event catalog with rationale is the right idea.

      Gaps

      Need stronger proof that the listed events are actually collected end-to-end, not just documented as intent.

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.