3.3 Audit & Accountability1 ptPOA&M-eligible

3.3.8 — Protect your logs from tampering

Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

Audit data and tools are protected from unauthorized access or change.

What it actually means

An attacker's first move is often to erase the logs. Audit records and the logging tools themselves must be protected from unauthorized access, modification, and deletion — typically by shipping logs off the source system to a write-protected central repository.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in Audit & Accountability (3.3)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.