NIST 800-171 R-3.3.8
Protect Audit Information and Tools
Official citation: 3.3.8
Class: core · Severity: high
Statement of the obligation — verify against source
3.3.8
What it means
Protect audit information — the records, log settings, and reports — and the logging tools themselves from unauthorized access, modification, and deletion, limiting their use to authorized individuals. This is the technical side of protection; physical protection of audit media is covered by the media-protection and physical-protection requirements.
Educational reference only — not legal advice. Consult a qualified assessor or attorney for binding compliance determinations.