NIST 800-171 · Audit and Accountability
Requirement 3.3.1
- SPRS weight
- SPRS weight: 5
- POA&M eligibility
- Not POA&M-eligible
- Assessment objectives
- 6 assessment objectives
Official requirement text
Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity
Assessment objectives
Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.
- 3.3.1[a]audit logs needed (i.e., event types to be logged) to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity are specified.
- 3.3.1[b]the content of audit records needed to support monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity is defined.
- 3.3.1[c]audit records are created (generated).
- 3.3.1[d]audit records, once created, contain the defined content.
- 3.3.1[e]retention requirements for audit records are defined.
- 3.3.1[f]audit records are retained as defined.
Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.