HomeControl Library › 3.3.1
3.3 Audit & Accountability5 pts

3.3.1 — Create and retain audit logs

Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.

You log the events needed to investigate, and you keep them.

What it actually means

Audit logging is, with access control, one of the two areas assessors find most often broken. You have to define which events you log, actually capture them across the in-scope systems, and retain them long enough to investigate an incident. 'We have logs somewhere' isn't it — coverage and retention are the test.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library