1Overview
AU.L2-3.3.6 makes audit records usable on demand. It requires an audit record reduction and report generation capability, so that when an investigation is needed, the organization can turn a large volume of raw logs into focused analysis and reports rather than sifting by hand. It is a one-point requirement and may be deferred on a plan of action.
Audit logs accumulate quickly, and in raw form a large volume of records is nearly unusable for a time-sensitive investigation. This control asks for two related capabilities: reduction, which filters and focuses the records so an analyst can concentrate on what matters, and report generation, which produces readable output on demand. Together they turn a heap of logs into something a person can actually investigate with, which is the difference between having records and being able to use them when it counts.
Provide audit record reduction and report generation to support on-demand analysis and reporting.
The two capabilities answer a practical question: when something happens, how fast can the organization find and present what the logs show. Reduction narrows the records to the relevant subset, and report generation turns that subset into readable output, both on demand rather than after days of manual work. The control does not require altering the original records; reduction operates on copies or through queries so the source records remain intact for the protection required by 3.3.8.
2The Assessment Objectives
NIST SP 800-171A frames 3.3.6 around two objectives: provide reduction, and provide report generation.
An audit record reduction capability that supports on-demand analysis is provided. The organization can filter and focus its audit records for analysis.
A report generation capability that supports on-demand reporting is provided. The organization can produce readable reports from its audit records when needed.
The two objectives are reduction and reporting, both on demand. The common gap is having raw logs with no capability to reduce or report on them, so that in an investigation the records exist but cannot be turned into usable analysis quickly. The assessor looks for a working capability to focus and present the records, not merely their presence.
3Failure Patterns
The failures are about raw logs with no means to focus or present them.
Raw logs only
Where records can only be read in raw form, an investigation means manually sifting through volume, which is slow and error-prone. A reduction capability that filters to the relevant records is what the control asks for.
No reporting capability
Without report generation, findings have to be assembled by hand each time, which does not support on-demand reporting. A capability to produce readable output from the records satisfies objective [b].
Capability that alters the source
A reduction approach that modifies the original records would conflict with the protection required elsewhere. Reduction should work on copies or through queries so the source records remain intact.
Capability no one can use
A tool that technically exists but that no one is trained to use does not support on-demand analysis in practice. The capability has to be usable by the people who would run an investigation.
4Ownership
This is an IT-owned control, usually satisfied by the same platform that collects and retains the logs.
| Role | Responsibility for this control |
|---|---|
| IT and system administrator | Provides and maintains the reduction and reporting capability, typically within the log platform. Owns the technical evidence. |
| Security or compliance lead | Confirms the capability supports on-demand analysis and reporting and that staff can use it. |
| Program lead | Ensures the capability remains available and retains evidence of it. |
5Tooling
The control is delivered by the query, filtering, and reporting features of the log collection platform.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | SIEM or log platform search and filtering | Reduction of records to the relevant subset for on-demand analysis. |
| [b] | Report generation in the log platform | Readable reports produced from the records on demand. |
| Integrity | Query-based access to retained records | Analysis that operates without altering the protected source records. |
The caveat is that the capability has to be usable and preserve the source. A platform that offers reduction and reporting satisfies the control only if it is available for on-demand use and does not alter the original records. The assessor examines whether the organization can focus and report on its records when needed, so a demonstrable, usable capability is what counts.
6Evidence
The satisfied version of 3.3.6 shows working reduction and reporting over the retained records.
| Evidence | What it demonstrates |
|---|---|
| Reduction capability | Objective [a]. The search and filtering that focuses records on demand. |
| Report generation capability | Objective [b]. The production of readable reports from the records. |
| Sample report or query | Objectives [a], [b]. A demonstration of on-demand analysis and reporting. |
The evidence should show that the organization can reduce and report on its audit records on demand, which a sample query and report demonstrate. The capability within the log platform, shown in use, is the clearest demonstration of the control.
Records you cannot search are records you cannot use
A heap of raw logs is nearly useless in a time-sensitive investigation, and this control asks for the reduction and reporting that turn storage into a usable tool. Standing up on-demand search and reporting over the retained records is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.3.6. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.3.6[a] and 3.3.6[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov