NIST SP 800-171 & CMMC 2.0 Control 3.3.5 Requirement:

Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

NIST SP 800-171 & CMMC 2.0 3.3.5 Requirement Explanation:

You must review, analyze, and report audit records to help detect and respond to security incidents in a timely manner for the purpose of investigation and corrective actions. .

Example NIST SP 800-171 & CMMC 2.0 3.3.5 Implementation:

Use your security information and event management (SIEM) system to analyze logs collected across your systems to help identify unauthorized activity.

NIST SP 800-171 & CMMC 2.0 3.3.5 Scenario(s):

- Scenario 1:

One of your employee's accounts was taken over by an attacker. You disable the account to prevent the attacker from causing further damage. Using your SIEM, you review audit logs from various systems and are able to determine other systems the attacker was able to access using the compromised account.
 

Discover Our NIST SP 800-171 & CMMC 2.0 Solutions:

 /assets/images/app/complaince_accelerator.gif

Compliance Accelerator

Power through compliance. Meet and maintain your NIST SP 800-171 & CMMC 2.0 compliance requirements.
 /assets/images/app/quantum_accelerator.gif

Quantum Assessor

Transform your business. Create new revenue streams and provide scalability for your NIST SP 800-171 and CMMC 2.0 services.
 /assets/images/app/supply_chain_verifier.gif

Supply Chain Verifier

Trust is everything. Verify, monitor, and support subcontactor compliance.