1Overview
AU.L2-3.3.5 is the second five-point requirement in the family, and it turns scattered logs into insight. It requires that the organization correlate its audit review, analysis, and reporting processes, so that indications of unlawful, unauthorized, suspicious, or unusual activity can be investigated across sources rather than one log at a time. It cannot be deferred on a plan of action.
A single log entry rarely tells the whole story. An attack shows up as a pattern across sources: a failed logon here, a privilege change there, an unusual data access somewhere else, each unremarkable alone but revealing when connected. This control asks the organization to bring its review, analysis, and reporting together so those connections can be seen, which in practice means collecting logs where they can be correlated and having a process that looks across them. Its five-point weight reflects that detection depends on correlation; logs that are never brought together hide the very patterns an investigation needs.
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.
The word "correlate" is the heart of the control. It is not enough to review each log in isolation; the review, analysis, and reporting processes have to be connected so that activity spanning multiple systems can be seen as one picture. This is where central log collection stops being a convenience and becomes the mechanism that makes correlation possible. The control is met when the processes are genuinely correlated rather than running in separate silos.
2The Assessment Objectives
NIST SP 800-171A frames 3.3.5 around two objectives: define the review, analysis, and reporting processes, and correlate them.
Audit record review, analysis, and reporting processes for investigation and response are defined. The organization has processes for reviewing, analyzing, and reporting on audit records.
Defined audit record review, analysis, and reporting processes are correlated. Those processes are connected so activity across sources can be seen together.
The two objectives are the existence of review, analysis, and reporting processes and their correlation. The common gap is at objective [b], where processes exist per system but are never brought together, so activity that spans systems, the signature of a real intrusion, goes undetected. The assessor looks for correlation across sources, not isolated per-log review.
3Failure Patterns
The failures are about siloed review and the absence of any place where logs come together.
Logs reviewed in isolation
Where each system's logs are reviewed on their own, a pattern that spans systems is invisible, because no one sees the pieces together. Correlation requires the review, analysis, and reporting to draw on the combined record, which per-system review cannot do.
No central collection
Without a place where logs are gathered, correlation is impractical, since an analyst would have to manually assemble records from many systems. Central collection is usually the precondition that makes objective [b] achievable.
Collection without analysis
Logs gathered centrally but never analyzed satisfy the plumbing without the process, leaving objective [a] unmet in substance. Correlation is a process applied to the collected records, not merely the fact of collection.
Reporting that goes nowhere
Analysis that produces no reporting for investigation and response leaves findings stranded. The processes have to connect through to reporting so that a correlated finding actually drives a response.
4Ownership
This is an IT and security-owned control, and its work is building central collection and a correlation and analysis process on top of it.
| Role | Responsibility for this control |
|---|---|
| Security or compliance lead | Defines the review, analysis, and reporting processes and ensures they are correlated across sources. Owns the process evidence. |
| IT and system administrator | Builds the central collection that feeds correlation and maintains the analysis tooling. |
| Program lead | Confirms the correlation process operates and that findings reach reporting, retaining the records. |
5Tooling
The control is delivered by central log collection and a correlation and analysis capability, typically a SIEM, plus the process that uses it.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Defined review, analysis, and reporting procedures | The documented processes applied to audit records for investigation and response. |
| [b] collection | Central log collection or SIEM | A single place where records from many systems come together, making correlation possible. |
| [b] correlation | Correlation rules and analysis | The connecting of activity across sources so cross-system patterns are seen. |
| Reporting | Alerting and reporting from the analysis | Delivery of correlated findings to investigation and response. |
The caveat is that collection is necessary but not sufficient; the correlation and analysis process is what satisfies the control. A SIEM that gathers logs but is never used to correlate leaves objective [b] unmet in practice. The assessor examines whether activity spanning systems can actually be investigated together, so the process on top of the collection has to be real.
6Evidence
The satisfied version of 3.3.5 shows defined processes and correlation across sources.
| Evidence | What it demonstrates |
|---|---|
| Review, analysis, and reporting procedures | Objective [a]. The defined processes for audit records. |
| Central collection configuration | Objective [b]. The gathering of logs that makes correlation possible. |
| Correlation rules or analysis records | Objective [b]. Evidence that activity across sources is connected. |
| Reporting output | Objectives [a], [b]. Correlated findings delivered for investigation and response. |
The evidence should show that the review, analysis, and reporting are correlated across sources, not run per system, which central collection plus a correlation process demonstrates. Configuration of the collection, the correlation rules or analysis records, and the resulting reporting together are the clearest demonstration, and because this control cannot sit on a plan of action, the correlation has to be operating at the time of assessment.
An intrusion hides in the gaps between logs
Real attacks show up as patterns across systems, and an organization that reviews each log alone sees only harmless fragments. Building central collection and a correlation process that lets the pattern emerge is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.3.5. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.3.5[a] and 3.3.5[b]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing AU.L2-3.3.5 among the five-point derived security requirements. ecfr.gov