Requirements / Audit and Accountability (AU)
AU.L2-3.3.5
Audit Correlation
Official Source Material
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
Determine if:
- [a] audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity are defined; and
- [b] defined audit record review, analysis, and reporting processes are correlated.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Correlate means the logs, the review, and the response work as one system.
Objective [a] asks you to define review, analysis, and reporting processes aimed at suspicious activity, and [b] asks that they connect instead of running independently. Cover both readings of connect. Collect logs into one place so events from different systems can be compared. Write the procedure that turns a suspicious finding into an incident under your incident response plan.
Central collection is what makes correlation demonstrable.
When tenant logs, endpoint logs, and firewall logs land in one log workspace, correlation is a query across sources. The assessment guide accepts manual correlation with well defined and managed procedures for small companies. A documented recurring review that compares sources also works. It is just harder to demonstrate than a query.
A year of zero findings undermines you.
A review process that never escalates anything looks like a process that does not run. Record triage outcomes even when they are benign: the sign-in alert that turned out to be a traveling employee is evidence the pipeline from log to review to decision works.
AU.L2-3.3.5 is a five point requirement with no POA&M path.
32 CFR 170.24 assigns it five points. 32 CFR 170.21 keeps a five point requirement off a POA&M, the plan of action and milestones that lets certain gaps be closed after assessment. Treat the link between logging and response as day one work.
What falls short
- Logs collected and even reviewed, with no defined path from a suspicious finding to incident response. The processes exist but are not correlated, so [b] fails.
Edge cases
- The data an endpoint detection tool collects can stand in for operating system event logs. Define it as your endpoint source under AU.L2-3.3.1, let this requirement's processes read from it, and keep the definitions aligned so the assessor sees one coherent logging story.