- Ship logs off the systems that generate them; a copy the compromised host cannot reach is the practical core of this requirement.
- Use immutability or retention-lock features where the platform offers them, and scope log-platform administration as its own role rather than bundling it into general admin.
- Treat the service credentials the log pipeline uses as audit-tool access too — they are the quiet path to tampering.
03.03.08 — Protection of Audit Information
03.03 Audit and Accountability · NIST SP 800-171 Rev. 3
Requires protecting audit information and audit logging tools from unauthorized access, modification, and deletion, and authorizing management of audit logging functionality to only a subset of privileged users or roles.
Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.
NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems ↗NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI ↗What this requirement is after
The first thing a competent intruder does with admin access is edit the story. Audit records and the tools that produce them must resist unauthorized access, change, and deletion — and the right to administer logging itself belongs to fewer people than hold admin rights generally.
Merges Rev. 2's 3.3.8 (protecting audit information and tools) and 3.3.9 (restricting audit management to a privileged subset) into one requirement.
Brilliant at the Basics practices that support this requirement
The campaign’s twenty practices are a priority list, not a control catalog, and none of them works this requirement’s substance directly. It still applies to you if it is in your contract’s scope: address it through your own implementation and the related artifacts below, and treat the absence of a mapping here as honesty, not permission to skip it.
Implementation considerations and evidence
- Access configuration on log storage and tooling showing the restricted admin subset
- Immutability or retention-lock settings, or the forwarding architecture
- A dated access review of who can manage logging
Templates and worksheets with a mapped relationship
No artifact in the library names this requirement yet. The library index groups everything by category and practice.
Where this came from in Rev. 2
Sources and review status
| Primary sources | NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI |
|---|---|
| Review status | Pending NIST SME review |
| Content version | 1.0 |
| Updated |