When assessing a contractor's implementation of CMMC practices, you examine its SystemSecurity Plan (SSP) to identify its documented measures for audit reduction and reporting. They have a dedicated section in their SSP addressing the Audit and Accountability requirements. You proceed to interview their information security personnel, who informed you that the contractor has a dedicated Security Operations Center (SOC) and uses Splunk to reduce and report audit logs. What key features regarding the deployment of Splunk for AU.L2-3.3.6 -- Reduction & Reporting would you be interested in assessing?
Comprehensive and Detailed In-Depth Explanatio n:
AU.L2-3.3.6 requires 'audit reduction and report generation capabilities.' Key features to assess in Splunk are filtering to reduce logs and analysis/reporting (C), directly meeting objectives [a] and [b]. RBAC (A) relates to AU.L2-3.3.8, retention (B) to AU.L2-3.3.2, and dashboards (D) aren't required, per CMMC focus.
Extract from Official CMMC Documentation:
CMMC Assessment Guide Level 2 (v2.0), AU.L2-3.3.6: 'Assess tools for [a] reducing logs via filters, [b] generating reports with analysis.'
NIST SP 800-171A, 3.3.6: 'Examine reduction and reporting functions.'
Resources:
https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.0_FINAL_202112016_508.pdf
Adelina
2 months agoCarey
2 months agoLenna
3 months agoElbert
3 months agoMabel
3 months agoArlene
4 months agoSarah
4 months agoGeorgeanna
4 months agoLynelle
4 months agoOdelia
4 months agoNelida
4 months agoDesire
5 months agoStephaine
5 months agoShawnda
5 months agoWhitney
5 months agoRamonita
5 months agoMargot
6 months agoKanisha
6 months agoCamellia
6 months agoSilvana
7 months agoTruman
7 months agoElli
7 months agoGlendora
7 months agoFrancene
7 months agoTasia
8 months agoPauline
8 months agoTambra
2 months agoBulah
2 months agoJennifer
5 months agoLashanda
6 months ago