When assessing a contractor's implementation of CMMC practices, you examine its SystemSecurity Plan (SSP) to identify its documented measures for audit reduction and reporting. They have a dedicated section in their SSP addressing the Audit and Accountability requirements. You proceed to interview their information security personnel, who informed you that the contractor has a dedicated Security Operations Center (SOC) and uses Splunk to reduce and report audit logs. What key features regarding the deployment of Splunk for AU.L2-3.3.6 -- Reduction & Reporting would you be interested in assessing?
Comprehensive and Detailed In-Depth Explanatio n:
AU.L2-3.3.6 requires 'audit reduction and report generation capabilities.' Key features to assess in Splunk are filtering to reduce logs and analysis/reporting (C), directly meeting objectives [a] and [b]. RBAC (A) relates to AU.L2-3.3.8, retention (B) to AU.L2-3.3.2, and dashboards (D) aren't required, per CMMC focus.
Extract from Official CMMC Documentation:
CMMC Assessment Guide Level 2 (v2.0), AU.L2-3.3.6: 'Assess tools for [a] reducing logs via filters, [b] generating reports with analysis.'
NIST SP 800-171A, 3.3.6: 'Examine reduction and reporting functions.'
Resources:
https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.0_FINAL_202112016_508.pdf
Lenna
10 hours agoElbert
6 days agoMabel
11 days agoArlene
16 days agoSarah
21 days agoGeorgeanna
26 days agoLynelle
1 month agoOdelia
1 month agoNelida
1 month agoDesire
2 months agoStephaine
2 months agoShawnda
2 months agoWhitney
2 months agoRamonita
2 months agoMargot
3 months agoKanisha
3 months agoCamellia
3 months agoSilvana
4 months agoTruman
4 months agoElli
4 months agoGlendora
4 months agoFrancene
4 months agoTasia
4 months agoPauline
5 months agoJennifer
2 months agoLashanda
3 months ago