DKDavid Koran& Associates
Home The CMMC Guide Part III · Audit and Accountability AU.L2-3.3.5
The CMMC Guide · Audit and Accountability Family

AU.L2-3.3.5  Audit Correlation

Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

Family
Audit and AccountabilityAU, 9 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
TwoPer NIST SP 800-171A

1Overview

AU.L2-3.3.5 is the second five-point requirement in the family, and it turns scattered logs into insight. It requires that the organization correlate its audit review, analysis, and reporting processes, so that indications of unlawful, unauthorized, suspicious, or unusual activity can be investigated across sources rather than one log at a time. It cannot be deferred on a plan of action.

A single log entry rarely tells the whole story. An attack shows up as a pattern across sources: a failed logon here, a privilege change there, an unusual data access somewhere else, each unremarkable alone but revealing when connected. This control asks the organization to bring its review, analysis, and reporting together so those connections can be seen, which in practice means collecting logs where they can be correlated and having a process that looks across them. Its five-point weight reflects that detection depends on correlation; logs that are never brought together hide the very patterns an investigation needs.

The requirement · NIST SP 800-171 Rev 2, 3.3.5

Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

The word "correlate" is the heart of the control. It is not enough to review each log in isolation; the review, analysis, and reporting processes have to be connected so that activity spanning multiple systems can be seen as one picture. This is where central log collection stops being a convenience and becomes the mechanism that makes correlation possible. The control is met when the processes are genuinely correlated rather than running in separate silos.

2The Assessment Objectives

NIST SP 800-171A frames 3.3.5 around two objectives: define the review, analysis, and reporting processes, and correlate them.

[a]

Audit record review, analysis, and reporting processes for investigation and response are defined. The organization has processes for reviewing, analyzing, and reporting on audit records.

MeetsDefined processes for how audit records are reviewed, analyzed, and reported for investigation and response.
FailsNo processes exist, so audit records are looked at ad hoc or not at all.
[b]

Defined audit record review, analysis, and reporting processes are correlated. Those processes are connected so activity across sources can be seen together.

MeetsLogs are collected centrally and correlated, so a pattern spanning several systems can be investigated as one.
FailsEach system's logs are reviewed separately, so cross-system patterns are never seen.

The two objectives are the existence of review, analysis, and reporting processes and their correlation. The common gap is at objective [b], where processes exist per system but are never brought together, so activity that spans systems, the signature of a real intrusion, goes undetected. The assessor looks for correlation across sources, not isolated per-log review.

3Failure Patterns

The failures are about siloed review and the absence of any place where logs come together.

Logs reviewed in isolation

Where each system's logs are reviewed on their own, a pattern that spans systems is invisible, because no one sees the pieces together. Correlation requires the review, analysis, and reporting to draw on the combined record, which per-system review cannot do.

No central collection

Without a place where logs are gathered, correlation is impractical, since an analyst would have to manually assemble records from many systems. Central collection is usually the precondition that makes objective [b] achievable.

Collection without analysis

Logs gathered centrally but never analyzed satisfy the plumbing without the process, leaving objective [a] unmet in substance. Correlation is a process applied to the collected records, not merely the fact of collection.

Reporting that goes nowhere

Analysis that produces no reporting for investigation and response leaves findings stranded. The processes have to connect through to reporting so that a correlated finding actually drives a response.

The common root
This control fails when logs stay in silos. An intrusion reveals itself as a pattern across systems, and an organization that reviews each log separately sees only unremarkable fragments. Correlation, usually through central collection and analysis, is what lets the pattern emerge.

4Ownership

This is an IT and security-owned control, and its work is building central collection and a correlation and analysis process on top of it.

RoleResponsibility for this control
Security or compliance leadDefines the review, analysis, and reporting processes and ensures they are correlated across sources. Owns the process evidence.
IT and system administratorBuilds the central collection that feeds correlation and maintains the analysis tooling.
Program leadConfirms the correlation process operates and that findings reach reporting, retaining the records.
See also: This control builds on the records created under AU.L2-3.3.1 and connects to the incident response family, which acts on what correlation surfaces.

5Tooling

The control is delivered by central log collection and a correlation and analysis capability, typically a SIEM, plus the process that uses it.

ObjectivesToolingWhat it provides
[a]Defined review, analysis, and reporting proceduresThe documented processes applied to audit records for investigation and response.
[b] collectionCentral log collection or SIEMA single place where records from many systems come together, making correlation possible.
[b] correlationCorrelation rules and analysisThe connecting of activity across sources so cross-system patterns are seen.
ReportingAlerting and reporting from the analysisDelivery of correlated findings to investigation and response.

The caveat is that collection is necessary but not sufficient; the correlation and analysis process is what satisfies the control. A SIEM that gathers logs but is never used to correlate leaves objective [b] unmet in practice. The assessor examines whether activity spanning systems can actually be investigated together, so the process on top of the collection has to be real.

6Evidence

The satisfied version of 3.3.5 shows defined processes and correlation across sources.

EvidenceWhat it demonstrates
Review, analysis, and reporting proceduresObjective [a]. The defined processes for audit records.
Central collection configurationObjective [b]. The gathering of logs that makes correlation possible.
Correlation rules or analysis recordsObjective [b]. Evidence that activity across sources is connected.
Reporting outputObjectives [a], [b]. Correlated findings delivered for investigation and response.

The evidence should show that the review, analysis, and reporting are correlated across sources, not run per system, which central collection plus a correlation process demonstrates. Configuration of the collection, the correlation rules or analysis records, and the resulting reporting together are the clearest demonstration, and because this control cannot sit on a plan of action, the correlation has to be operating at the time of assessment.

An intrusion hides in the gaps between logs

Real attacks show up as patterns across systems, and an organization that reviews each log alone sees only harmless fragments. Building central collection and a correlation process that lets the pattern emerge is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.3.5. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.3.5[a] and 3.3.5[b]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing AU.L2-3.3.5 among the five-point derived security requirements. ecfr.gov
← Previous in Audit and Accountability
AU.L2-3.3.4 · Audit Logging Failure Alerts
Next in Audit and Accountability →
AU.L2-3.3.6 · Audit Reduction and Reporting
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry AU.L2-3.3.5 · Edition 2026.1 · Last reviewed July 12, 2026