Audit Correlation
Practice statement
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
Quoted verbatim from NIST SP 800-171 Rev. 2 §3.3.5.Source
The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.
Assessment Objectives(2)
An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.
- [a]
audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined; and
1 example covers this
- [b]
defined audit record review, analysis, and reporting processes are correlated.
1 example covers this
Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.
Implementation examples(1)
Submit your own example- addresses
AU.L2-3.3.5Audit Correlation
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
[a]
audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined; and[b]
defined audit record review, analysis, and reporting processes are correlated.
One investigation timeline across identity, endpoint, network, and file-server events
ControlVerdict Corpus@cv-corpusOSCJul 31, 2026Community is just starting — add yours. No verdicts yet.Implementation
AO coverage. Addresses both Audit Correlation objectives: the review, analysis, and reporting processes are defined, and those processes are correlated across sources rather than run independently.
Defined processes [a]. Three tiers are written down. Continuous: correlation searches run on a schedule and raise notable events. Daily: the analyst triages the notable queue with a documented decision (escalate, tune, or close with reason). Weekly: a trend review looks at what was tuned and whether the tuning hid something. Each tier names its owner, its input, and its output artifact.
Correlation in practice [b]. Events are normalized so the same user, host, and address fields carry the same names regardless of source. Correlation searches join across sources rather than alerting on one signal — for example, a privileged role activation with no matching change ticket and an unusual source address; or an endpoint detection followed within 15 minutes by unusual read volume on an enclave file share. Every notable event opens with an entity-scoped timeline that pulls all four sources for that user and host over the surrounding window.
Handoff to response. A notable event that escalates becomes a case, and the case carries the correlated timeline as its first artifact, so the incident process starts with evidence instead of a search box.
Maintenance. Monthly review of correlation search performance (false positives, misses found later). Quarterly purple-team exercise: a benign but detectable action is performed and the correlation must produce the timeline. Field normalization is re-validated after any source schema change.
Accepted gap. One SaaS app timestamps only to the minute, which limits ordering precision inside a one-minute window. Analysts are told to treat its ordering as approximate; sequence-critical conclusions rely on the sources with sub-second timestamps.
What the evidence looks like
- Written three-tier review, analysis, and reporting process with owners
- Correlation search definitions showing multi-source joins
- Field normalization mapping across the four source types
- A closed case with its correlated timeline attached
- Quarterly purple-team exercise record and the resulting tuning
Environment
~700 employees with 80 in the enclave. Identity, endpoint detection, firewall, and file-server audit events all index into a single analytics platform.Tools
Discussion(0)
No discussion on this control yet
Edge cases, scoping questions, and “would this pass?” scenarios belong here.
Sign in to start a thread.