Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.3.4OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.3.4Audit failure alerting

3.3 Audit and Accountability · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Alert in the event of an audit logging process failure.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Logging fails quietly — a full disk, a dead agent, an expired credential on the forwarder — and an attacker's favorite log is the one that stopped being written weeks ago. Someone must be alerted when the logging process itself breaks.

Across revisions

Carried into Rev. 3 as Response to Audit Logging Process Failures (03.03.04), with the alert timeframe and required response actions becoming organization-defined parameters.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Monitor the health of the pipeline, not just the systems: agent heartbeat, ingestion volume per source, and storage headroom each catch a different failure.
  • Route the alert to a named person with a defined response, and decide in advance what happens while logging is down — keep operating, or halt the affected activity.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Alerting configuration for logging-process failures with the named recipient
  • A record of a test or real failure alert and the response that followed
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated