AU.L2-3.3.1[b] – Identify the types of events that the system must log.
This objective requires your organization to define and document which types of events must be logged based on risk, compliance, and operational need—particularly for systems that handle Controlled Unclassified Information (CUI).
AU.L2-3.3.5[a] – Identify where audit logs are being retained.
This objective requires your organization to identify and document where your audit logs are stored, particularly for systems that handle Controlled Unclassified Information (CUI). This includes both local and centralized log storage locations.
AU.L2-3.3.2[a] – Identify the information system components that provide audit record generation capability.
This objective requires your organization to identify all systems, applications, and infrastructure components that have the ability to generate audit records, especially those that process or support access to Controlled Unclassified Information (CUI).
AU.L2-3.3.8[a] – Identify personnel or roles that are notified of audit logging processing failures.
This objective requires your organization to define and document who is notified when a system experiences audit logging failures, such as when logs cannot be generated, stored, forwarded, or retained—especially in systems handling Controlled Unclassified Information (CUI).
AU.L2-3.3.3[c] – Examine audit record content to verify that records of the events being reviewed contain sufficient information to support the review.
This objective ensures that the audit records your systems generate actually include the necessary details to support meaningful security reviews—especially when monitoring systems that process Controlled Unclassified Information (CUI).
AU.L2-3.3.8[c] – Examine audit log failure notification mechanisms to verify that personnel or roles are notified of audit logging processing failures.
This objective focuses on validating that your configured alerting mechanisms are functional and aligned with your defined responsibilities—ensuring the right people are notified when audit logging fails, especially on systems handling Controlled Unclassified Information (CUI).
AU.L2-3.3.2[b] – Examine system configurations to verify that audit record generation is enabled for the identified system components.
This objective requires organizations to verify through configuration settings that all system components identified as having audit capabilities are actually set up to generate audit records, particularly those that process or secure Controlled Unclassified Information (CUI).
AU.L2-3.3.4[a] – Identify the information system components that provide time stamps.
This objective requires your organization to identify all systems and devices that generate time-stamped audit records, particularly those supporting the logging of Controlled Unclassified Information (CUI) activities.
AU.L2-3.3.8[b] – Examine system configurations to verify that personnel or roles are notified of audit logging processing failures.
This objective ensures your systems are technically configured to alert assigned personnel when there are failures in audit log processing, such as: Log services being disabled Log files not being generated or forwarded Storage capacity being exceeded Log forwarding services losing connectivity This applies to systems that process or protect Controlled Unclassified Information (CUI).
AU.L2-3.3.3[b] – Examine audit record review procedures to determine if audit records are reviewed.
This objective ensures that your organization has documented procedures for reviewing audit logs and that those procedures are followed regularly, especially for systems that store, process, or transmit Controlled Unclassified Information (CUI).