Under active development Content is continuously updated and improved

3.3.8Audit and Accountability - Derived

Derived Requirement

>Control Description

Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

>Discussion

Audit information includes all information (e.g., audit records, audit log settings, and audit reports) needed to successfully audit system activity. Audit logging tools are those programs and devices used to conduct audit and logging activities. This requirement focuses on the technical protection of audit information and limits the ability to access and execute audit logging tools to authorized individuals.

Physical protection of audit information is addressed by media protection and physical and environmental protection requirements.

>Cross-Framework Mappings

>Assessment Interview Topics

Questions assessors commonly ask

Process & Governance:

  • What documented policies and procedures address audit and accountability - derived for CUI systems?
  • Who is accountable for implementing and maintaining audit and accountability - derived controls?
  • How frequently are audit and accountability - derived requirements reviewed, and what triggers updates?
  • What process ensures changes to systems maintain compliance with audit and accountability - derived requirements?
  • How are exceptions to audit and accountability - derived requirements documented and approved?

Technical Implementation:

  • What technical controls enforce audit and accountability - derived in your CUI environment?
  • How are audit and accountability - derived controls configured and maintained across all CUI systems?
  • What automated mechanisms support audit and accountability - derived compliance?
  • How do you validate that audit and accountability - derived implementations achieve their intended security outcome?
  • What compensating controls exist if primary audit and accountability - derived controls cannot be fully implemented?

Evidence & Documentation:

  • What documentation proves audit and accountability - derived is implemented and operating effectively?
  • Can you provide configuration evidence showing how audit and accountability - derived is technically enforced?
  • What audit logs or monitoring data demonstrate ongoing audit and accountability - derived compliance?
  • Can you show evidence of a recent review or assessment of audit and accountability - derived controls?
  • What artifacts would you provide to a CMMC assessor to demonstrate audit and accountability - derived compliance?

Ask AI

Configure your API key to use AI features.