// ITSP.10.171 · FAMILY 03 · 8 REQUIREMENTS
Audit and accountability
Last verified: 2026-10-05
// REQUIREMENTS
| Identifier | Requirement | Level 1 |
|---|---|---|
| 03.03.01 | Event logging | |
| 03.03.02 | Audit record content | |
| 03.03.03 | Audit record generation | |
| 03.03.04 | Response to audit logging process failures | |
| 03.03.05 | Audit record review, analysis, and reporting | |
| 03.03.06 | Audit record reduction and report generation | |
| 03.03.07 | Time stamps | |
| 03.03.08 | Protection of audit information |
// INTENT
When something happens, you can reconstruct it.
// WHAT A FIRST ASSESSMENT FINDS
Logs exist wherever vendors defaulted them on, retained until the disk fills, reviewed never.
// THE WORK
Decide which events matter (authentication, privilege use, access to the enclave, changes to security configuration), aggregate them somewhere central even if it's a modest syslog box, retain them for a defined period, protect them from tampering, and review them on a schedule a human keeps. An assessor asking for last Tuesday needs to get last Tuesday.
// HOW WE CAN INTERPRET IT
// TEMPLATES FOR THIS FAMILY
References
- Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)Canadian Centre for Cyber Securitycyber.gc.ca
- NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsNISTcsrc.nist.gov
Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.