1Overview
AU.L2-3.3.3 keeps auditing from going stale. It requires that the organization review and update the events it logs, so that what is captured continues to match what needs to be seen as the environment and the threats change. It is a one-point requirement and may be deferred on a plan of action, though the review it asks for is what keeps the whole family relevant.
An audit configuration set once and never revisited slowly drifts out of usefulness. New systems appear, new threats emerge, and events that once mattered give way to others, yet the logged event set stays frozen unless someone reviews it. This control asks the organization to define when it will review its logged events, to actually perform that review, and to update the event set based on what the review finds. It is the maintenance loop that keeps 3.3.1 from decaying into a configuration that no longer serves.
Review and update logged events.
The requirement is short but has a cycle inside it: decide when to review, review, and update. The point is not a one-time configuration but a recurring check that the logged events still align with the organization's needs and risks, adjusting them when they do not. The organization defines the review cadence, and the control is met when that review demonstrably happens and leads to updates when warranted.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.3.3 into three objectives: define the review process, review the logged events, and update them based on the review.
A process for determining when to review logged events is defined. The organization has decided how often and under what conditions it reviews what it logs.
Event types being logged are reviewed in accordance with the defined review process. The review actually happens on the defined schedule.
Event types being logged are updated based on the review. The logged events change when the review shows they should.
The three objectives form a loop: define the review, perform it, and act on it. The common gap is at objectives [b] and [c], where a review cadence exists on paper but is never carried out or never produces a change, so the logged events remain frozen. The assessor looks for evidence that reviews happen and that they lead to updates when warranted.
3Failure Patterns
The failures are about set-and-forget logging and reviews that never change anything.
Set once, never revisited
Logging configured at initial setup and never reviewed drifts out of alignment as the environment changes, which fails objective [a] outright. A defined review cadence is what keeps the logged events current.
A review that never happens
A written review process that is never actually performed leaves the events frozen despite the plan. Objective [b] requires the review to occur on its cadence, with a record that it did.
Reviews that never lead to change
Reviews that happen but never result in any update to the logged events suggest a formality rather than a genuine check, especially in an environment that has clearly changed. Objective [c] expects the review to drive updates when the environment or threats warrant them.
No record of the review
A review that occurred informally, with nothing to show for it, cannot be demonstrated. The objectives are met through evidence of the review and any resulting updates, so dated records carry the requirement.
4Ownership
This is an IT and security-owned control whose work is a recurring review rather than a technical build.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Defines the review cadence, conducts the review of logged events, and drives updates. Owns the review records. |
| IT and system administrator | Applies the updates to the logging configuration when the review calls for them. |
| Program lead | Ensures the review happens on its cadence and after significant change, and retains the records. |
5Tooling
The control is largely a process, supported by whatever holds the audit configuration and the review record.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | A documented review schedule | The defined cadence and triggers for reviewing logged events. |
| [b] | Review checklist and records | A repeatable review of the logged event set with a record that it occurred. |
| [c] | Change record for audit configuration | Documentation of updates to the logged events resulting from the review. |
The caveat is that the control is satisfied by the review actually happening and producing change when warranted, not by a schedule alone. A cadence on paper with no performed reviews leaves objectives [b] and [c] unmet, so the evidence is the record of reviews and the updates they produced. The assessor looks for a review that lives, not a plan that sits.
6Evidence
The satisfied version of 3.3.3 shows a defined review, reviews that occurred, and updates that followed.
| Evidence | What it demonstrates |
|---|---|
| Review schedule | Objective [a]. The defined cadence and triggers for review. |
| Review records | Objective [b]. Dated evidence the logged events were reviewed. |
| Update records | Objective [c]. Changes to the logged events resulting from the review. |
The evidence should show the review loop operating: a cadence, reviews that happened, and updates when the review called for them. Dated review records paired with the resulting configuration changes are the clearest demonstration of the control.
Auditing set once will drift out of usefulness
Logged events configured at setup and never revisited slowly stop matching the environment they watch, and this control asks for the modest recurring review that keeps them current. Building a review cadence that actually adjusts what is logged is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.3.3. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.3.3[a] through 3.3.3[c]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov