Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.3.1OFFICIAL STATEMENT BELOWBASIC REQUIREMENTPENDING NIST SME REVIEW

3.3.1Audit log creation and retention

3.3 Audit and Accountability · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

When something goes wrong, the logs must let you reconstruct what happened, who did it, and when — which means the right events are captured and kept long enough to matter. A breach discovered in month four is investigated with month-one logs, or it is not investigated at all.

Across revisions

Rev. 3 splits the substance: selecting the event types to log becomes Event Logging (03.03.01), while generating and retaining the records becomes Audit Record Generation (03.03.03), with record content promoted to its own requirement (03.03.02).

Mapped practices

Brilliant at the Basics practices that support this requirement

Operational supportModerate confidence

Why: Passive OT monitoring continuously produces records of network activity on control segments — and its alert-investigation routine consumes them — giving the OT estate a usable record base for monitoring and investigation that controllers and HMIs cannot generate themselves.

What this does not claim: Sensor observations are not system audit logs: the requirement asks for created and retained audit records across organizational systems, with retention decided deliberately, and a monitoring platform's rolling capture may not qualify. Provides evidence relevant to the requirement for the OT estate only, and only where OT falls within the assessed boundary.

Practice-side activities
  • Retain sensor records and alerts under a deliberate retention decision rather than the platform default
  • Route OT detections into the same investigation and record-keeping process as IT events
Evidence this produces
  • Retained OT monitoring records covering a defined period
  • Alert investigation records with disposition

Where this holds: Holds where OT segments are within the assessed CUI boundary; contributes nothing to audit logging for the IT estate.

Review status: Pending OT SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Decide which events actually support investigation — authentication, privilege use, access to CUI stores, configuration changes — rather than logging everything and retaining nothing.
  • Centralize collection so logs survive the compromise of the machine that produced them, and set retention deliberately instead of accepting each product's default.
  • Cover the cloud and SaaS services where CUI actually lives; tenant audit logs are in scope even though no server in the office produces them.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • Logging configuration exports for the systems inside the boundary
  • The written retention decision and the storage settings that implement it
  • A demonstrated retrieval of records from months back, not just from yesterday

Suggested owners, derived from the mapped practices and artifacts: OT engineer · IT leader. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated