CMMCpedia Download

Requirements / Audit and Accountability (AU)

AU.L2-3.3.8

Audit Protection

Official Source Material

Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

Determine if:

  1. [a] audit information is protected from unauthorized access;
  2. [b] audit information is protected from unauthorized modification;
  3. [c] audit information is protected from unauthorized deletion;
  4. [d] audit logging tools are protected from unauthorized access;
  5. [e] audit logging tools are protected from unauthorized modification; and
  6. [f] audit logging tools are protected from unauthorized deletion.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Access control carries all six objectives.

Restrict who can read audit information for [a] and who can open the tools for [d]. Grant nobody modification rights for [b] and [e]. Confine deletion to the few who manage retention for [c] and [f]. The evidence is a role definition plus the list of people who hold the role.

Forward logs off the systems that generate them.

An administrator whose actions are being logged can clear a local log. A copy that ships to a central store as events occur means clearing the local log destroys nothing, and the clearing itself becomes an event in the central copy.

The tools and settings are protected, not just the data.

Objectives [d], [e], and [f] cover the audit configuration and tooling. Restrict who can change audit policy, who can reconfigure log collection, and who can administer the log platform. Keep that list aligned with the subset you define under AU.L2-3.3.9.

In a cloud tenant this is a role review.

List which directory roles can read, export, or purge audit data, and cut the list to the people who need it. Protect exported log archives with the same restraint, because an export anyone can read undoes [a] no matter how tight the portal is.

What falls short

  • Every administrator holding rights to purge audit data. Deletion is not confined to an authorized few, so [c] and [f] fail.

Edge cases

  • A three person company can put log platform access in one admin's hands when a second person receives regular log reports for review. Define the arrangement in writing, because the small headcount is not the problem and a missing definition would be.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.