CMMC 2.0
Audit and Accountability

CMMC 2.0 AU.L2-3.3.3: Event Review

Review the set of events selected for logging and update it as the environment and threat picture change.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 44 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • NIST-CSF-RS.AN-08 An incident's magnitude is estimated and validated

SOC 2 · 5 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents

CIS Controls v8 · 4 controls

  • CIS-13.1 Centralize Security Event Alerting
  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.11 Conduct Audit Log Reviews

ISO 27001:2022 · 4 controls

  • 5.25 Assessment and decision on information security events
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.15 Logging
  • 8.16 Monitoring activities

ISO 27002:2022 · 3 controls

  • 5.25 Assessment and decision on information security events
  • 8.15 Logging
  • 8.16 Monitoring activities

NIST SP 800-53 Rev 5 · 3 controls

PCI DSS 4.0 · 3 controls

  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 10.4.1.1 10.4.1.1 Automated mechanisms used for audit log review
  • 12.4.2 12.4.2 Quarterly reviews that personnel follow security procedures
  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-LT-2 Enable threat detection for identity and access management

C5 (Germany) · 2 controls

  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-OPS-13 Logging and Monitoring - Identification of Events

NIST SP 800-171 Rev 3 · 2 controls

  • E8-UAH-ML3 User Application Hardening - Maturity Level 3
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components

FedRAMP High · 1 control

FedRAMP Moderate · 1 control

HIPAA Security Rule · 1 control

ISO/IEC 42001:2023 · 1 control

  • 9.1 Monitoring, measurement, analysis and evaluation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Audit and Accountability

You are reading one control. How much of CMMC 2.0 have you already done?

CMMC 2.0 AU.L2-3.3.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 44 it maps to, and the evidence behind each claim, over MCP and REST.