NIST 800-171 · Audit and Accountability

Requirement 3.3.8

SPRS weight
SPRS weight: 1
POA&M eligibility
POA&M-eligible
Assessment objectives
6 assessment objectives

Official requirement text

Protect audit information and audit logging tools from unauthorized access, modification, and deletion.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.3.8[a]audit information is protected from unauthorized access.
  2. 3.3.8[b]audit information is protected from unauthorized modification.
  3. 3.3.8[c]audit information is protected from unauthorized deletion.
  4. 3.3.8[d]audit logging tools are protected from unauthorized access.
  5. 3.3.8[e]audit logging tools are protected from unauthorized modification.
  6. 3.3.8[f]audit logging tools are protected from unauthorized deletion.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.