CMMC AU.3.048 - Centralize Audit Information

CMMC AU.3.048 - Centralize Audit Information

Requirement text: AU.3.048: Collect audit information (e.g., logs) into one or more central repositories.

DISCUSSION FROM SOURCE: CMMC
Aggregate and store audit logs in a central location. Central repositories enable analysis by
storing audit record content needed for analysis in a common location and format. Storing
audit logs in central repositories also protects audit information. The repository has the
available infrastructure, capacity, and protection mechanisms to meet the organization’s
audit requirements. Policy and local laws may place requirements on the location and
structure of the repositories.

CMMC CLARIFICATION
Aggregate and store audit logs in a centralized location or locations within the organization.
Storing audit logs in a centralized location supports orchestration, automation, correlation,
and analysis activities by enabling a full picture of the audit logs, and can support automated
analysis capabilities including correlation of events across the enterprise. Ensure that the
central repository has the appropriate infrastructure, including protection mechanisms, and
the capacity level to meet the logging requirements of the organization.

Example
You are in charge of IT operations in your organization. Your responsibilities include
reviewing audit logs. You consolidate all audit logs in a common format and into a
centralized logging infrastructure that may consist of one or more servers. By doing this,
you enable centralized analysis of your audit logs. This increases situational awareness
across your network. In addition, you are able to better protect your audit logs by storing
them in one centralized location.

References
• CMMC
• CIS Controls v7.1 6.5
• CERT RMM v1.2 COMP:SG3.SP1
• NIST SP 800-53 Rev 4 AU-6(4)
    • Related Articles

    • Audit and Accountability: SP 800-171 Security Family 3.3

      An audit is an independent review and examination of records and activities to assess the adequacy of system requirements and ensure compliance with established policies and operational procedures. An audit trail is a record of individuals who have ...
    • CMMC AU.3.049 - Protect Audit Information and Tools

      Requirement text: AU.3.049: Protect audit information and audit logging tools from unauthorized access, modification, and deletion. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 Audit information includes all information (e.g., audit records, ...
    • CMMC AU.2.042 - Retain System Audit Logs

      Requirement text: AU.2.042: Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. DISCUSSION FROM SOURCE: DRAFT NIST SP ...
    • CMMC AU.2.044 - Review Audit Logs

      Requirement text: AU.2.044: Review audit logs. DISCUSSION FROM SOURCE: CMMC Reviewing audit logs is a common control in information security. Organizations have the flexibility to determine which logs and specific events to review. The level of audit ...
    • CMMC AU.3.052 - Implement Audit Record Reduction

      Requirement text: AU.3.052: Provide audit record reduction and report generation to support on- demand analysis and reporting. DISCUSSION FROM SOURCE: DRAFT NIST SP 800-171 R2 Audit record reduction is a process that manipulates collected audit ...