Skip to content
ControlVerdict
AU.L2-3.3.9CMMC Level 2Level 2

Audit Management

Practice statement

Limit management of audit logging functionality to a subset of privileged users.

Quoted verbatim from NIST SP 800-171 Rev. 2 §3.3.9.Source

The source document’s non-normative “Discussion” section is not reproduced here. ControlVerdict quotes normative text verbatim or omits it — it never paraphrases a standard. Follow the source link above for the full context.

Assessment Objectives(2)

An assessor determines each objective separately. “Mostly implemented” is not a result — every objective below has to stand on its own.

  1. [a]

    a subset of privileged users granted access to manage audit logging functionality is defined; and

    1 example covers this

  2. [b]

    management of audit logging functionality is limited to the defined subset of privileged users.

    1 example covers this

Objective text quoted verbatim from NIST SP 800-171A via the CMMC Level 2 assessment guide.

Implementation examples(1)

Submit your own example
  • addresses
    AU.L2-3.3.9Audit Management
    Limit management of audit logging functionality to a subset of privileged users.
    • [a]

      a subset of privileged users granted access to manage audit logging functionality is defined; and
    • [b]

      management of audit logging functionality is limited to the defined subset of privileged users.

    Two named log administrators; analysts and engineers get read-only search

    ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
    Community is just starting — add yours. No verdicts yet.

    Implementation

    AO coverage. Addresses both Audit Management objectives: the subset of privileged users allowed to manage audit logging functionality is defined, and management is limited to that subset.

    Defined subset [a]. Two named individuals hold the log administrator role: the security lead and one platform engineer. The written definition also states what the role covers — ingest configuration, retention settings, detection rule changes, and role assignment within the platform — so there is no argument about which actions require it. A third person is trained and listed as the documented backup, eligible but not standing.

    Limiting management [b]. Everyone else is read-only. Analysts search and build saved searches but cannot alter ingest or retention; application owners see their own source and nothing else. The default role granted at onboarding was changed to read-only, which is what actually fixed the drift — the prior state came from a default, not a decision.

    Separation from the archive. Neither log administrator can delete from the write-once archive described in the AU.L2-3.3.8 example, so even the defined subset cannot destroy the record of what it did.

    Activation and visibility. The backup administrator activates the role through time-bound eligibility with a ticket reference. Every action taken under the log administrator role is itself logged to the archive and reviewed weekly by someone who does not hold the role.

    Maintenance. Quarterly attestation: export current platform role assignments, compare against the two named holders plus the eligible backup, and have the enclave owner sign. Offboarding or role change removes platform administration the same day.

    Accepted gap. The outsourced provider occasionally needs platform administration for an upgrade. Access is granted as a time-bound activation on a named guest account for the change window, is session-recorded, and is revoked at window close rather than left standing.

    What the evidence looks like

    • Written role definition listing the two holders and what the role covers
    • Platform role assignment export showing read-only for everyone else
    • Default onboarding role configuration after the change
    • Weekly review record of log-admin actions, signed by a non-holder
    • Time-bound activation ticket and revocation record for the last provider upgrade

    Environment

    Twelve-person IT and security team. Analysts previously held platform administrator rights simply because that was the default role assigned at onboarding.

    Tools

Discussion(0)

No discussion on this control yet

Edge cases, scoping questions, and “would this pass?” scenarios belong here.

Sign in to start a thread.