CMMC 1.0 Practice AU.2.044 Requirement:

Review audit logs.

CMMC 1.0 AU.2.044 Requirement Explanation:

By periodically reviewing audit logs you can identify security incidents in your environment.

Example CMMC 1.0 AU.2.044 Implementation:

Determine a time in which you periodically (e.g. weekly) review system logs to identify security incidents. Create a list systems and and event types to review.

CMMC 1.0 AU.2.044 Scenario(s):

- Scenario 1:

Alice is a system administrator at a small company. She has a list of key systems whose audit logs she wants to review. She also has a list of event types and IDs she wants to review. Alice sets a side time every week to log into her listed systems to review their audit logs.

