<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://cooey.wiki/index.php?action=history&amp;feed=atom&amp;title=SPA_Objectives_-_SIEM_Tool</id>
	<title>SPA Objectives - SIEM Tool - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://cooey.wiki/index.php?action=history&amp;feed=atom&amp;title=SPA_Objectives_-_SIEM_Tool"/>
	<link rel="alternate" type="text/html" href="https://cooey.wiki/index.php?title=SPA_Objectives_-_SIEM_Tool&amp;action=history"/>
	<updated>2026-05-01T08:37:32Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.42.3</generator>
	<entry>
		<id>https://cooey.wiki/index.php?title=SPA_Objectives_-_SIEM_Tool&amp;diff=146&amp;oldid=prev</id>
		<title>Liatris: Created page with &quot;== When is a SIEM an SPA? == A SIEM is an SPA when it ingests/aggregates logs from one or more CUI assets.  == Assessment Objectives to Assess == AU.L2-3.3.1 - SYSTEM AUDITING [c,d,f]  * A SIEM will shows audit records are created, contain the defined content, and are retained as defined.  AU.L2-3.3.2 - USER ACCOUNTABILITY [b]  * The SIEM will show that audit records contain the defined content necessary to trace users to their actions.  AU.L2-3.3.4 - AUDIT FAILURE ALERT...&quot;</title>
		<link rel="alternate" type="text/html" href="https://cooey.wiki/index.php?title=SPA_Objectives_-_SIEM_Tool&amp;diff=146&amp;oldid=prev"/>
		<updated>2025-09-25T13:30:54Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== When is a SIEM an SPA? == A SIEM is an SPA when it ingests/aggregates logs from one or more CUI assets.  == Assessment Objectives to Assess == AU.L2-3.3.1 - SYSTEM AUDITING [c,d,f]  * A SIEM will shows audit records are created, contain the defined content, and are retained as defined.  AU.L2-3.3.2 - USER ACCOUNTABILITY [b]  * The SIEM will show that audit records contain the defined content necessary to trace users to their actions.  AU.L2-3.3.4 - AUDIT FAILURE ALERT...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== When is a SIEM an SPA? ==&lt;br /&gt;
A SIEM is an SPA when it ingests/aggregates logs from one or more CUI assets.&lt;br /&gt;
&lt;br /&gt;
== Assessment Objectives to Assess ==&lt;br /&gt;
AU.L2-3.3.1 - SYSTEM AUDITING [c,d,f]&lt;br /&gt;
&lt;br /&gt;
* A SIEM will shows audit records are created, contain the defined content, and are retained as defined.&lt;br /&gt;
&lt;br /&gt;
AU.L2-3.3.2 - USER ACCOUNTABILITY [b]&lt;br /&gt;
&lt;br /&gt;
* The SIEM will show that audit records contain the defined content necessary to trace users to their actions.&lt;br /&gt;
&lt;br /&gt;
AU.L2-3.3.4 - AUDIT FAILURE ALERTING [c]&lt;br /&gt;
&lt;br /&gt;
* A SIEM may be able to show that identified personnel/roles are alerted in an audit logging process failure.&lt;br /&gt;
&lt;br /&gt;
AU.L2-3.3.5 - AUDIT CORRELATION [b]&lt;br /&gt;
&lt;br /&gt;
* A SIEM can help show review, analysis, and reporting processes are correlated.&lt;br /&gt;
&lt;br /&gt;
AU.L2-3.3.6 - REDUCTION &amp;amp; REPORTING [a,b]&lt;br /&gt;
&lt;br /&gt;
* A SIEM can be used to show on-demand analysis and reporting of audit logs&lt;br /&gt;
&lt;br /&gt;
AU.L2-3.3.8 - AUDIT PROTECTION [a-f]&lt;br /&gt;
&lt;br /&gt;
* The SIEM will show how audit information and tools are protected from unauthorized access, modification, and deletion.&lt;br /&gt;
&lt;br /&gt;
AU.L2-3.3.9 - AUDIT MANAGEMENT [b]&lt;br /&gt;
&lt;br /&gt;
* The SIEM would need to be shown to demonstrate that a subset of users have access to manage the SIEM.&lt;br /&gt;
&lt;br /&gt;
IR.L2-3.6.1 - INCIDENT HANDLING [c,d]&lt;br /&gt;
&lt;br /&gt;
* A SIEM will likely help support detection and analysis during an incident.&lt;br /&gt;
&lt;br /&gt;
SI.L2-3.14.6 - MONITOR COMMUNICATIONS FOR ATTACKS [a,b,c]&lt;br /&gt;
&lt;br /&gt;
* A SIEM can show that the system, inbound traffic, and outbound traffic are monitored to detect attacks.&lt;br /&gt;
&lt;br /&gt;
SI.L2-3.14.7 - IDENTIFY UNAUTHORIZED USE [b]&lt;br /&gt;
&lt;br /&gt;
* A SIEM will likely show that unauthorized use is identified.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Assessment Objectives that won&amp;#039;t likely be Assessed ==&lt;br /&gt;
AU.L2-3.3.3 - EVENT REVIEW&lt;br /&gt;
&lt;br /&gt;
* A SIEM will likely not contain evidence that event types to be logged are reviewed and updated.&lt;br /&gt;
&lt;br /&gt;
AU.L2-3.3.7 - AUTHORITATIVE TIME SOURCE&lt;br /&gt;
&lt;br /&gt;
* No AOs require a SIEM to demonstrate that an authoritative time source is selected and used.&lt;/div&gt;</summary>
		<author><name>Liatris</name></author>
	</entry>
</feed>