When assessing a contractor's implementation of CMMC practices, you examine its SystemSecurity Plan (SSP) to identify its documented measures for audit reduction and reporting. They have a dedicated section in their SSP addressing the Audit and Accountability requirements. You proceed to interview their information security personnel, who informed you that the contractor has a dedicated Security Operations Center (SOC) and uses Splunk to reduce and report audit logs. What key features regarding the deployment of Splunk for AU.L2-3.3.6 -- Reduction & Reporting would you be interested in assessing?
Comprehensive and Detailed In-Depth Explanatio n:
AU.L2-3.3.6 requires 'audit reduction and report generation capabilities.' Key features to assess in Splunk are filtering to reduce logs and analysis/reporting (C), directly meeting objectives [a] and [b]. RBAC (A) relates to AU.L2-3.3.8, retention (B) to AU.L2-3.3.2, and dashboards (D) aren't required, per CMMC focus.
Extract from Official CMMC Documentation:
CMMC Assessment Guide Level 2 (v2.0), AU.L2-3.3.6: 'Assess tools for [a] reducing logs via filters, [b] generating reports with analysis.'
NIST SP 800-171A, 3.3.6: 'Examine reduction and reporting functions.'
Resources:
https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.0_FINAL_202112016_508.pdf
Adelina
4 months agoCarey
4 months agoLenna
5 months agoElbert
5 months agoMabel
5 months agoArlene
5 months agoSarah
5 months agoGeorgeanna
5 months agoLynelle
6 months agoOdelia
6 months agoNelida
6 months agoDesire
6 months agoStephaine
6 months agoShawnda
6 months agoWhitney
7 months agoRamonita
7 months agoMargot
7 months agoKanisha
8 months agoCamellia
8 months agoSilvana
8 months agoTruman
8 months agoElli
9 months agoGlendora
9 months agoFrancene
9 months agoTasia
9 months agoPauline
9 months agoTambra
3 months agoBulah
4 months agoJennifer
7 months agoLashanda
7 months ago