CMMCpedia Download

Requirements / Audit and Accountability (AU)

AU.L2-3.3.3

Event Review

Official Source Material

Review and update logged events.

Determine if:

  1. [a] a process for determining when to review logged events is defined;
  2. [b] event types being logged are reviewed in accordance with the defined review process; and
  3. [c] event types being logged are updated based on the review.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

This requirement is about the list of events you log, not about reading logs.

The assessment guide states that review of the audit records themselves belongs to AU.L2-3.3.5 and AU.L2-3.3.6. Here you review the logging configuration: whether the event types you chose under AU.L2-3.3.1 still cover your needs. Bring log review records to this requirement and you have answered a different question.

Define the trigger for the review in writing.

Objective [a] asks for a process that says when the review happens. Name a cadence and the events that force an early review: at least annually, after a security incident, and after a major system change. The CMMC rule at 32 CFR 170.4 defines periodically as at least annually, and an open ended cadence gives an assessor nothing to verify.

Hold the review and keep the artifact even when nothing changes.

Objective [b] wants evidence the process ran. Meeting minutes, a ticket, or a dated one page review all work. A review that concludes the current event set is sufficient still satisfies [b] when the conclusion is recorded.

The strongest evidence for [c] is one real change.

A change ticket that adds an event type after a review, such as enabling failed logon events or removable media logging once a gap surfaced, shows the loop closes. If an incident revealed activity you were not logging, the update you made afterward is exactly what [c] describes.

Fixed cloud logging does not make this requirement not applicable.

When a service such as Microsoft 365 controls what its audit log collects, review whether the collected set meets your needs and record the conclusion. Supplement with endpoint or network logging where it does not. Claiming N/A because you cannot change the vendor's event set earns a Not Met, because the review process is yours no matter who owns the settings.

What falls short

  • Logging configured at system setup and never revisited. There is no process for [a] and no review for [b].
  • Log review dashboards and alert triage records offered as evidence. They show you read the logs, not that you reviewed which event types are logged, so [b] is unmet.
  • N/A asserted because the cloud provider fixes what is collected. The review process in [a] and [b] is yours, so the requirement applies.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.