3.3 Audit & Accountability3 pts

3.3.2 — Trace actions to individual users

Ensure that the actions of individual system users can be uniquely traced to those users so they can be held accountable for their actions.

Every logged action can be tied back to a specific person.

What it actually means

Logging events is only useful if you can tell who did what. Because every user has a unique account (see 3.5.1) and you're not using shared logins, your audit records carry an individual identity — so an action can be traced to one person, not 'someone on the shared admin account.'

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Audit & Accountability (3.3)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.