When assessing a contractor's implementation of CMMC practices, you examine its SystemSecurity Plan (SSP) to identify its documented measures for audit reduction and reporting. They have a dedicated section in their SSP addressing the Audit and Accountability requirements. You proceed to interview their information security personnel, who informed you that the contractor has a dedicated Security Operations Center (SOC) and uses Splunk to reduce and report audit logs. What key features regarding the deployment of Splunk for AU.L2-3.3.6 -- Reduction & Reporting would you be interested in assessing?
Comprehensive and Detailed In-Depth Explanatio n:
AU.L2-3.3.6 requires 'audit reduction and report generation capabilities.' Key features to assess in Splunk are filtering to reduce logs and analysis/reporting (C), directly meeting objectives [a] and [b]. RBAC (A) relates to AU.L2-3.3.8, retention (B) to AU.L2-3.3.2, and dashboards (D) aren't required, per CMMC focus.
Extract from Official CMMC Documentation:
CMMC Assessment Guide Level 2 (v2.0), AU.L2-3.3.6: 'Assess tools for [a] reducing logs via filters, [b] generating reports with analysis.'
NIST SP 800-171A, 3.3.6: 'Examine reduction and reporting functions.'
Resources:
https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.0_FINAL_202112016_508.pdf
Adelina
22 days agoCarey
27 days agoLenna
2 months agoElbert
2 months agoMabel
2 months agoArlene
2 months agoSarah
2 months agoGeorgeanna
2 months agoLynelle
3 months agoOdelia
3 months agoNelida
3 months agoDesire
3 months agoStephaine
3 months agoShawnda
3 months agoWhitney
4 months agoRamonita
4 months agoMargot
4 months agoKanisha
5 months agoCamellia
5 months agoSilvana
5 months agoTruman
5 months agoElli
5 months agoGlendora
6 months agoFrancene
6 months agoTasia
6 months agoPauline
6 months agoTambra
11 days agoBulah
17 days agoJennifer
4 months agoLashanda
4 months ago