CMMC AU.2.044 - Review Audit Logs

CMMC AU.2.044 - Review Audit Logs

Requirement text: AU.2.044: Review audit logs.

DISCUSSION FROM SOURCE: CMMC
Reviewing audit logs is a common control in information security. Organizations have the
flexibility to determine which logs and specific events to review. The level of audit log review
should be determined based on a risk assessment or similar activity.

CMMC CLARIFICATION
You should ensure that your organization reviews its audit logs. Logs should be checked
regularly, organizations with small environments may be able to do this manually. The
process of reviewing audit logs varies by organization. The intent of this practice is to
become familiar with the logs being automatically created on the systems present in your
organization and identify key events in the logs that might indicate malicious activity. Larger
organizations may need automation to complete this task with success.

Example
You are the administrator for a company with a small IT environment. You know the
importance of reviewing audit logs. Every week you log on to the Windows server as an
admin user, open the Event Viewer and check for signs that the log files have been altered:
Windows event ID 104 – Event Log was Cleared, event ID 1102 – Audit Log was Cleared),
event ID 4719 – System audit policy was changed. Look for login and new user created
events: Windows event IDs 4624 (failure) and 4625 (success)) and event IDs 4728, 4732 and
4756 – User added to Privileged Group.

References
• CMMC
• CIS Controls v7.1 6.7
• NIST CSF v1.1 PR.PT-1
• CERT RMM v1.2 COMP:SG3.SP1
• NIST SP 800-53 Rev 4 AU-6


    • Related Articles

    • CMMC AU.4.054 - Review Audit Activity

      Requirement text: AU.4.054: Review audit information for broad activity in addition to per-machine activity. DISCUSSION FROM SOURCE: CMMC The full scope of adversary activity may not be apparent from analyzing a single machine. A broad perspective is ...
    • Audit and Accountability: SP 800-171 Security Family 3.3

      An audit is an independent review and examination of records and activities to assess the adequacy of system requirements and ensure compliance with established policies and operational procedures. An audit trail is a record of individuals who have ...
    • CMMC AU.2.042 - Retain System Audit Logs

      Requirement text: AU.2.042: Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. DISCUSSION FROM SOURCE: DRAFT NIST SP ...
    • CMMC AU.3.052 - Implement Audit Record Reduction

      Requirement text: AU.3.052: Provide audit record reduction and report generation to support on- demand analysis and reporting. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 Audit record reduction is a process that manipulates collected audit ...
    • CMMC AU.3.051 - Correlate Audit Records

      Requirement text: AU.3.051: Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 ...