Skip to content
ControlVerdict
AU.L2-3.3.5CMMC Level 2Level 2

Audit Correlation

Practice statement

Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.3.5.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined; and

    1 example covers this

  2. [b]

    defined audit record review, analysis, and reporting processes are correlated.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AU.L2-3.3.5Audit Correlation
    Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
    • [a]

      audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined; and
    • [b]

      defined audit record review, analysis, and reporting processes are correlated.

    One investigation timeline across identity, endpoint, network, and file-server events

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses both Audit Correlation objectives: the review, analysis, and reporting processes are defined, and those processes are correlated across sources rather than run independently.

    Defined processes [a]. Three tiers are written down. Continuous: correlation searches run on a schedule and raise notable events. Daily: the analyst triages the notable queue with a documented decision (escalate, tune, or close with reason). Weekly: a trend review looks at what was tuned and whether the tuning hid something. Each tier names its owner, its input, and its output artifact.

    Correlation in practice [b]. Events are normalized so the same user, host, and address fields carry the same names regardless of source. Correlation searches join across sources rather than alerting on one signal — for example, a privileged role activation with no matching change ticket and an unusual source address; or an endpoint detection followed within 15 minutes by unusual read volume on an enclave file share. Every notable event opens with an entity-scoped timeline that pulls all four sources for that user and host over the surrounding window.

    Handoff to response. A notable event that escalates becomes a case, and the case carries the correlated timeline as its first artifact, so the incident process starts with evidence instead of a search box.

    Maintenance. Monthly review of correlation search performance (false positives, misses found later). Quarterly purple-team exercise: a benign but detectable action is performed and the correlation must produce the timeline. Field normalization is re-validated after any source schema change.

    Accepted gap. One SaaS app timestamps only to the minute, which limits ordering precision inside a one-minute window. Analysts are told to treat its ordering as approximate; sequence-critical conclusions rely on the sources with sub-second timestamps.

    What the evidence looks like

    • Written three-tier review, analysis, and reporting process with owners
    • Correlation search definitions showing multi-source joins
    • Field normalization mapping across the four source types
    • A closed case with its correlated timeline attached
    • Quarterly purple-team exercise record and the resulting tuning

    Environment

    ~700 employees with 80 in the enclave. Identity, endpoint detection, firewall, and file-server audit events all index into a single analytics platform.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.