3.3 Audit & Accountability5 pts

3.3.5 — Correlate and review your logs

Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

You actually review and connect log data to spot suspicious activity.

What it actually means

Collecting logs isn't enough — you have to use them. This control wants a process that brings records together (ideally a SIEM), reviews and correlates them, and surfaces suspicious activity for investigation. It's a 5-pointer because logs nobody looks at protect nobody.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Audit & Accountability (3.3)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.