DKDavid Koran& Associates
Home The CMMC Guide Part III · Audit and Accountability AU.L2-3.3.3
The CMMC Guide · Audit and Accountability Family

AU.L2-3.3.3  Review Logged Events

Review and update logged events.

Family
Audit and AccountabilityAU, 9 requirements
Point Value
1Lower weight, but not POA&M exempt
POA&M Eligible
YesOne-point requirement, may be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

AU.L2-3.3.3 keeps auditing from going stale. It requires that the organization review and update the events it logs, so that what is captured continues to match what needs to be seen as the environment and the threats change. It is a one-point requirement and may be deferred on a plan of action, though the review it asks for is what keeps the whole family relevant.

An audit configuration set once and never revisited slowly drifts out of usefulness. New systems appear, new threats emerge, and events that once mattered give way to others, yet the logged event set stays frozen unless someone reviews it. This control asks the organization to define when it will review its logged events, to actually perform that review, and to update the event set based on what the review finds. It is the maintenance loop that keeps 3.3.1 from decaying into a configuration that no longer serves.

The requirement · NIST SP 800-171 Rev 2, 3.3.3

Review and update logged events.

The requirement is short but has a cycle inside it: decide when to review, review, and update. The point is not a one-time configuration but a recurring check that the logged events still align with the organization's needs and risks, adjusting them when they do not. The organization defines the review cadence, and the control is met when that review demonstrably happens and leads to updates when warranted.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.3.3 into three objectives: define the review process, review the logged events, and update them based on the review.

[a]

A process for determining when to review logged events is defined. The organization has decided how often and under what conditions it reviews what it logs.

MeetsA defined cadence, such as an annual review plus review after significant change, for revisiting the logged event set.
FailsNo review process exists, so the logged events are whatever was set at the start.
[b]

Event types being logged are reviewed in accordance with the defined review process. The review actually happens on the defined schedule.

MeetsThe logged event set is reviewed on the defined cadence, with the review recorded.
FailsA review process is written but never carried out, so the events are never revisited.
[c]

Event types being logged are updated based on the review. The logged events change when the review shows they should.

MeetsThe review leads to updates, adding events for new systems or threats and removing noise, with the change recorded.
FailsReviews occur but never result in any change, suggesting they are not genuine.

The three objectives form a loop: define the review, perform it, and act on it. The common gap is at objectives [b] and [c], where a review cadence exists on paper but is never carried out or never produces a change, so the logged events remain frozen. The assessor looks for evidence that reviews happen and that they lead to updates when warranted.

3Failure Patterns

The failures are about set-and-forget logging and reviews that never change anything.

Set once, never revisited

Logging configured at initial setup and never reviewed drifts out of alignment as the environment changes, which fails objective [a] outright. A defined review cadence is what keeps the logged events current.

A review that never happens

A written review process that is never actually performed leaves the events frozen despite the plan. Objective [b] requires the review to occur on its cadence, with a record that it did.

Reviews that never lead to change

Reviews that happen but never result in any update to the logged events suggest a formality rather than a genuine check, especially in an environment that has clearly changed. Objective [c] expects the review to drive updates when the environment or threats warrant them.

No record of the review

A review that occurred informally, with nothing to show for it, cannot be demonstrated. The objectives are met through evidence of the review and any resulting updates, so dated records carry the requirement.

The common root
This control fails through neglect rather than error. Auditing is configured once and left alone, and without a review loop it slowly stops matching the environment it is supposed to watch. The fix is a modest recurring review that actually adjusts what is logged.

4Ownership

This is an IT and security-owned control whose work is a recurring review rather than a technical build.

RoleResponsibility for this control
Security or compliance leadDefines the review cadence, conducts the review of logged events, and drives updates. Owns the review records.
IT and system administratorApplies the updates to the logging configuration when the review calls for them.
Program leadEnsures the review happens on its cadence and after significant change, and retains the records.
See also: This control maintains the logging established under AU.L2-3.3.1 and pairs with the review and analysis of AU.L2-3.3.5.

5Tooling

The control is largely a process, supported by whatever holds the audit configuration and the review record.

ObjectivesToolingWhat it provides
[a]A documented review scheduleThe defined cadence and triggers for reviewing logged events.
[b]Review checklist and recordsA repeatable review of the logged event set with a record that it occurred.
[c]Change record for audit configurationDocumentation of updates to the logged events resulting from the review.

The caveat is that the control is satisfied by the review actually happening and producing change when warranted, not by a schedule alone. A cadence on paper with no performed reviews leaves objectives [b] and [c] unmet, so the evidence is the record of reviews and the updates they produced. The assessor looks for a review that lives, not a plan that sits.

6Evidence

The satisfied version of 3.3.3 shows a defined review, reviews that occurred, and updates that followed.

EvidenceWhat it demonstrates
Review scheduleObjective [a]. The defined cadence and triggers for review.
Review recordsObjective [b]. Dated evidence the logged events were reviewed.
Update recordsObjective [c]. Changes to the logged events resulting from the review.

The evidence should show the review loop operating: a cadence, reviews that happened, and updates when the review called for them. Dated review records paired with the resulting configuration changes are the clearest demonstration of the control.

Auditing set once will drift out of usefulness

Logged events configured at setup and never revisited slowly stop matching the environment they watch, and this control asks for the modest recurring review that keeps them current. Building a review cadence that actually adjusts what is logged is part of the onsite readiness work this practice does.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.3.3. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.3.3[a] through 3.3.3[c]. csrc.nist.gov
  3. 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov
← Previous in Audit and Accountability
AU.L2-3.3.2 · User Accountability
Next in Audit and Accountability →
AU.L2-3.3.4 · Audit Logging Failure Alerts
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AU.L2-3.3.3 · Edition 2026.1 · Last reviewed July 12, 2026