Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
03.03.03OFFICIAL TITLEPENDING NIST SME REVIEW

03.03.03Audit Record Generation

03.03 Audit and Accountability · NIST SP 800-171 Rev. 3

Independent summary of the official requirement

Requires generating audit records for the event types selected under 03.03.01, with the record content defined under 03.03.02, and retaining those records for a time period consistent with the organization's records retention policy.

Rev. 3 requirement text is multi-part and parameterized with organization-defined values, so this site summarizes rather than reproduces it. The summary is independent — read the official publication for the binding wording.

NIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal SystemsNIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Independent interpretation

What this requirement is after

Deciding what to log and what a record contains means nothing until systems actually emit those records and keep them long enough to matter. This is the operational half: generation everywhere the decisions apply, and retention aligned with the organization's records policy rather than whatever the default rollover happens to be.

Across revisions

Splits generation and retention out of Rev. 2's 3.3.1 into an explicit requirement tied to the selections made under 03.03.01 and 03.03.02.

Mapped practices

Brilliant at the Basics practices that support this requirement

Doing the work

Implementation considerations and evidence

Implementation considerationsIndependent guidance — tailor to your environment
  • Reconcile the systems emitting logs against the asset inventory — the machine that never appears in the log platform is the one this requirement is about.
  • Set retention deliberately: long enough for investigations that start months late, affordable enough to survive budget review, and written into the records retention policy the requirement points at.
  • Watch for silent generation failures — stopped agents, filled quotas; the alerting in 03.03.04 depends on someone noticing here.
What operating evidence looks likeRecords worth retaining, not a submission checklist
  • A log-source coverage report reconciled against the inventory
  • Retention configuration and the records policy naming the period
Artifacts

Templates and worksheets with a mapped relationship

No artifact in the library names this requirement yet. The library index groups everything by category and practice.

The other revision

Where this came from in Rev. 2

Provenance

Sources and review status

Primary sourcesNIST SP 800-171 Rev. 3 — Protecting CUI in Nonfederal Systems · NIST SP 800-171A Rev. 3 — Assessing Security Requirements for CUI
Review statusPending NIST SME review
Content version1.0
Updated