Audit & Accountability
That system activity is logged, attributable to individuals, and reviewable — so misuse can be detected and reconstructed.
The 9 requirements, in plain language.
Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity
Ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions
Review and update logged events
Alert in the event of an audit logging process failure
Correlate audit record review, analysis, and reporting processes for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity
Provide audit record reduction and report generation to support on-demand analysis and reporting
Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
Protect audit information and audit logging tools from unauthorized access, modification, and deletion
Limit management of audit logging functionality to a subset of privileged users
One owner across the whole family — built, run, and proven.
Enclave builds these controls into the boundary as code; Cadence keeps them enforced between assessments; Attest proves them to the C3PAO against every objective.
See all fourteen families →Not sure which families your contract puts in scope?
A readiness check maps your environment to all 110 controls and tells you exactly where you stand.