Every logged action can be tied back to a specific person.
What it actually means
Logging events is only useful if you can tell who did what. Because every user has a unique account (see 3.5.1) and you're not using shared logins, your audit records carry an individual identity — so an action can be traced to one person, not 'someone on the shared admin account.'
Pass or fail — an assessor needs a "yes" to each
- Logs capture a unique user identity for actions.
- No shared/generic accounts that break attribution.
- You can answer 'who did this?' from the logs.
What to have ready
- Sample audit records showing per-user attribution
- Confirmation that shared accounts are eliminated
Where teams trip up
- Shared admin accounts that make 'who' unanswerable
- Service accounts used interactively by multiple people
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Audit & Accountability (3.3)
3.3.1 — Create and retain audit logs3.3.3 — Review and update what you log3.3.4 — Alert when logging breaks3.3.5 — Correlate and review your logs3.3.6 — Reduce logs and generate reports3.3.7 — Synchronize clocks for time stamps3.3.8 — Protect your logs from tampering3.3.9 — Limit who manages logging