Requirements / Audit and Accountability (AU)
AU.L2-3.3.6
Reduction & Reporting
Official Source Material
Provide audit record reduction and report generation to support on-demand analysis and reporting.
Determine if:
- [a] an audit record reduction capability that supports on-demand analysis is provided; and
- [b] a report generation capability that supports on-demand reporting is provided.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Reduction is filtering, and a query interface is a reduction capability.
Objective [a] does not demand an analytics platform. It asks that a person can turn a mass of raw records into a focused view when needed. The search in your cloud audit portal, a log workspace query, or a script over exported logs each qualify when they reach the log sources you defined under AU.L2-3.3.1.
A report is a saved, shareable answer.
Objective [b] is met when you can produce output someone else can read: exported query results, a scheduled summary, a filtered view saved to a file. Prepare a few canned questions, such as everything one account did in a day, and be ready to run them live, because on demand includes during the assessment.
Keep CUI out of the logging pipeline.
Logs are metadata: who, what, when, outcome. Configure logging so file contents never land in a record. A log platform that ingests CUI, the controlled unclassified information you protect, pulls itself into your CUI scope. A platform kept clean of CUI protects the environment without expanding it.
What falls short
- Raw log files in storage with no way to search or summarize them. Retention without reduction leaves [a] and [b] unmet.