Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
3.3.5OFFICIAL STATEMENT BELOWDERIVED REQUIREMENTPENDING NIST SME REVIEW

3.3.5Audit correlation

3.3 Audit and Accountability · NIST SP 800-171 Rev. 2 · The heading label is this site's navigational shorthand; the official language is the statement below.

Official requirement statement (verbatim)

Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity.

NIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

One log source rarely tells the whole story: the phishing click is in the mail logs, the token theft in the identity logs, the data pull in the file-access logs. Review, analysis, and reporting must connect across sources so suspicious activity is investigated as one event, not three curiosities.

Mapped practices

Brilliant at the Basics practices that support this requirement

Operational supportModerate confidence

Why: The practice's operating rhythm — investigate every alert, disposition it, feed OT detections into the wider response process — is the review-analysis-response loop this requirement wants, running on the OT sources most correlation processes omit.

What this does not claim: One well-run source is not correlation across sources: the requirement expects review and analysis connected across the organization's audit records — identity, endpoint, cloud — and the practice contributes the OT feed, not the joining. It should be evaluated within the organization's defined system boundary, where the OT segment may be a small part of the whole.

Practice-side activities
  • Investigate and disposition OT alerts as part of normal work
  • Integrate OT detections with the IT detection platform so one team sees the whole picture
Evidence this produces
  • Alert-investigation-rate tracking with dispositions
  • An investigation that connected an OT detection with IT-side records

Review status: Pending OT SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Aggregate sources into one searchable place first — correlation across five consoles is a manual process nobody performs twice.
  • Write down how a suspicious finding moves from review into investigation and response, so correlation feeds action rather than a dashboard.
  • At small scale, a weekly cross-source review by one named person is a legitimate correlation process; the discipline matters more than the tooling.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • The aggregation or SIEM configuration showing sources feeding one platform
  • An investigation record that demonstrably drew on more than one source

Suggested owners, derived from the mapped practices and artifacts: OT engineer. Ownership is a named person in your organization, not a role on a website.

Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this lands in Rev. 3

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated