Skip to content
Pass My CMMC
Practices Start Here Prep Timeline Glossary About

Audit-Accountability

AU.L2-3.3.3
AU.L2-3.3.3: Audit Review, Analysis, and Reporting
Regularly review and analyze audit logs to identify security events, then report findings to management.
medium
AU.L2-3.3.4
AU.L2-3.3.4: Audit Failure Alerting
Alert system administrators and security personnel immediately when audit logging or analysis failures occur.
medium
AU.L2-3.3.5
AU.L2-3.3.5: Audit Correlation
Correlate audit data from multiple sources to identify patterns and complex attack sequences that individual logs cannot detect.
hard
AU.L2-3.3.6
AU.L2-3.3.6: Audit Reduction and Report Generation
Create tools and processes to filter audit logs and generate reports that focus on security-relevant events rather than routine system activity.
medium
AU.L2-3.3.7
AU.L2-3.3.7: Authoritative Time Source
Synchronize all system clocks to a reliable, authoritative time source so audit logs are trustworthy and events can be correlated accurately.
easy
AU.L2-3.3.8
AU.L2-3.3.8: Audit Protection
Protect audit logs from unauthorized access, modification, and deletion to preserve their integrity as evidence.
medium
AU.L2-3.3.9
AU.L2-3.3.9: Audit Management
Limit audit log management functions (configuration, deletion, archival) to authorized individuals to prevent tampering.
medium

Pass My CMMC

Site

All Practices Start Here CMMC Levels Explained Assessment Day Glossary About

Popular Families

Access Control (AC) Incident Response (IR) System Protection (SC) All 14 families

Newsletter

Subscribe on Substack

© 2026 Pass My CMMC. This site provides general guidance based on real assessment experience. It is not legal, compliance, or professional advice. Your organization's situation is unique. Work with qualified professionals for formal assessment preparation.