Subcontractor CMMC Tracker

Audit and Accountability (AU): the 9 CMMC Level 2 requirements a subcontractor self-assesses

The Audit and Accountability family of NIST SP 800-171 Rev 2, as CMMC Level 2 numbers it: each requirement with the value it carries in the score, our statement of the clause, and the evidence an assessor asks for.

Where frameworks a subcontractor holds may supply evidence here

The requirements

9
CMMC L2 AU.L2-3.3.1System Auditing 5 points in the score

Generate and retain system audit logs in sufficient scope and detail to support monitoring, analysis, investigation and reporting of unlawful or unauthorized system activity.

What an assessor asks to see: Defined auditable event list and rationale for its scope; Logging configuration on in scope systems; Retention settings and evidence logs are retained for the defined period; Sample audit records showing captured content
Where subcontractors usually fall short: Logging enabled with default event sets never assessed for sufficiency; Retention shorter than investigation needs; In scope systems missing from logging coverage
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AU.L2-3.3.2User Accountability 3 points in the score

Ensure actions taken on the system can be traced uniquely to the individual user responsible so users can be held accountable.

What an assessor asks to see: Evidence of unique user identifiers with no shared accounts; Audit records showing the individual user attributed to actions; Controls tying privileged and service account use back to a person
Where subcontractors usually fall short: Shared or generic administrative accounts break attribution; Privileged actions logged under a role rather than a person; Service accounts used interactively
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AU.L2-3.3.3Event Review 1 point in the score

Review the set of events selected for logging and update it as the environment and threat picture change.

What an assessor asks to see: Records of periodic review of the logged event set; Change history showing updates to auditable events; Defined review frequency and owner
Where subcontractors usually fall short: Event set defined once and never revisited; Reviews performed with no resulting updates recorded; New systems added without event set review
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AU.L2-3.3.4Audit Failure Alerting 1 point in the score

Raise an alert when the audit logging process itself fails, so a loss of logging is noticed rather than silent.

What an assessor asks to see: Alert configuration for logging process failure and log storage exhaustion; Evidence of alerts reaching a monitored destination; Records of response to a logging failure
Where subcontractors usually fall short: Failure detection absent so logging stops unnoticed; Alerts generated but routed to an unmonitored mailbox; Storage capacity failures not treated as logging failures
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AU.L2-3.3.5Audit Correlation 5 points in the score

Bring audit review, analysis and reporting together across sources so signs of unlawful, unauthorized, suspicious or unusual activity can be investigated and answered.

What an assessor asks to see: Correlation capability configuration, for example SIEM rules; Evidence logs from multiple sources are aggregated; Investigation records showing correlated analysis
Where subcontractors usually fall short: Logs collected centrally but never correlated; Correlation rules present but untuned and unreviewed; Key sources absent from aggregation
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AU.L2-3.3.6Reduction & Reporting 1 point in the score

Provide audit record reduction and report generation capability that supports analysis and reporting on demand.

What an assessor asks to see: Tooling providing search, filter and report generation over audit records; Sample generated reports; Evidence reduction does not alter original records
Where subcontractors usually fall short: Raw logs only, with no practical analysis capability; Reporting possible only through vendor support requests; Reduction process modifies the source records
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AU.L2-3.3.7Time Stamps & Synchronization 1 point in the score

Synchronize internal system clocks against an authoritative time source so audit record time stamps are comparable across systems.

What an assessor asks to see: Authoritative time source identified and documented; Time synchronization configuration across in scope systems; Evidence of synchronization status and drift monitoring
Where subcontractors usually fall short: Systems synchronized to differing or local sources; Time zone handling inconsistent across log sources; Synchronization failures unmonitored
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AU.L2-3.3.8Audit Protection 1 point in the score

Prevent unauthorized access to, modification of, and deletion of both audit records and the tools that produce them.

What an assessor asks to see: Access controls on log stores and logging tools; Evidence of write once, forwarding or integrity protection for logs; Review showing administrators cannot silently delete their own activity
Where subcontractors usually fall short: Local administrators able to clear logs without trace; Log integrity protection absent; Logging tool configuration modifiable by general administrators
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)
CMMC L2 AU.L2-3.3.9Audit Management 1 point in the score

Restrict the ability to manage audit logging functionality to a limited subset of privileged users, separate from general administrators.

What an assessor asks to see: List of users authorized to manage audit logging; Configuration restricting audit management permissions; Evidence of separation from general system administration
Where subcontractors usually fall short: All administrators hold audit management rights; Subset defined on paper but not enforced technically; No review of who holds audit management privileges
Source: CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2)