// ITSP.10.171 · FAMILY 03 · 8 REQUIREMENTS

Audit and accountability

Last verified: 2026-10-05

// REQUIREMENTS

IdentifierRequirementLevel 1
03.03.01 Event logging
03.03.02 Audit record content
03.03.03 Audit record generation
03.03.04 Response to audit logging process failures
03.03.05 Audit record review, analysis, and reporting
03.03.06 Audit record reduction and report generation
03.03.07 Time stamps
03.03.08 Protection of audit information

// INTENT

When something happens, you can reconstruct it.

// WHAT A FIRST ASSESSMENT FINDS

Logs exist wherever vendors defaulted them on, retained until the disk fills, reviewed never.

// THE WORK

Decide which events matter (authentication, privilege use, access to the enclave, changes to security configuration), aggregate them somewhere central even if it's a modest syslog box, retain them for a defined period, protect them from tampering, and review them on a schedule a human keeps. An assessor asking for last Tuesday needs to get last Tuesday.

// HOW WE CAN INTERPRET IT

// TEMPLATES FOR THIS FAMILY

References

  1. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171)April 2025, updated October 2025
    Canadian Centre for Cyber Securitycyber.gc.ca
  2. NIST SP 800-171 Revision 3, Protecting Controlled Unclassified Information in Nonfederal Systems and OrganizationsRevision 3
    NISTcsrc.nist.gov

Outbound links open in a new tab. Source-pinned. If a vendor moves a doc, this block gets updated.