This objective requires your organization to confirm, through technical configuration, that your systems are generating audit logs for the events you have identified as required—especially for systems handling Controlled Unclassified Information (CUI).