Audit records for the systems that hold CUI
Collect, sign and keep the logs NIST 800-171 asks for, and see plainly what stays with you.
Requirements
| Clause | What it asks | ARRTECH |
|---|---|---|
| 800-171 3.3.1 | Create and retain audit logs for monitoring and investigation. | Classified events per source. → |
| 800-171 3.3.4 | Alert when audit logging fails. | A silent-source alert. → |
| 800-171 3.3.5 | Correlate audit review, analysis and reporting. | Correlation across sources. → |
| 800-171 3.3.8 | Protect audit information from unauthorized change. | A signature chain that breaks on change. → |
| 800-171 3.6.1 | An incident-handling capability. | Cases and playbook history. → |
| 800-171 3.8.7 | Control removable media. | Device control per user or computer. → |
| 800-171 3.14.6 | Monitor for attacks and indicators of attack. | MITRE-tagged classified events. → |
Logging
Record events in one form
ARRTECH SIEM classification rules turn vendor codes into common event categories, graded Informational to Critical, so one search covers every vendor. MITRE ATT&CK tactic and technique are columns on each classified event.
Integrity
Prove nobody changed your logs
ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.
Completeness
Know when logging stops
The Data Sources page shows each source’s status, last read time and a silent-source alert, so a missing source is visible before your assessor finds it.
Response
Track every incident to its close
A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report. ARRTECH SOAR opens incidents from SIEM alerts and keeps an execution history of playbook runs. The Operator node emails a person with up to five options and waits.
Media
Control removable media
ARRTECH DLP device control allows or blocks any device class or specific device by vendor, product or serial number, per user or computer, with a manager approval option.
Limits
Know what stays with you
No ARRTECH product produces the record for these requirements.
800-171 3.3.7
Clocks synchronized to an authoritative source. No ARRTECH product sets or records time synchronization. The record comes from your time servers’ configuration.
800-171 3.5.3
Multifactor authentication for privileged and network access. ARRTECH does not claim MFA to its consoles. The record comes from your identity system.
800-171 3.13.11
FIPS-validated cryptography to protect CUI. ARRTECH does not claim FIPS 140-3 validated cryptography.
800-171 3.13.16
CUI protected at rest. ARRTECH does not claim encryption at rest in its products.
By rule
Naming a clause is not a claim of certification.
800-171 3.3.1
Create and retain system audit logs and records. ARRTECH: classification rules turn vendor codes into common event categories, with retention set per source or per group.
800-171 3.3.4
Alert in the event of an audit logging process failure. ARRTECH: the Data Sources page shows each source’s status, last read time and a silent-source alert.
800-171 3.3.5
Correlate audit record review, analysis and reporting processes. ARRTECH: correlation rules link related events across sources. A saved query becomes a report, on a schedule.
800-171 3.3.8
Protect audit information and audit logging tools from unauthorized access, modification and deletion. ARRTECH: a signature chain that breaks on any change or missing file, and role-based rights on each log source.
800-171 3.6.1
Establish an operational incident-handling capability. ARRTECH: SIEM cases with type, severity, assignee and history, and SOAR incidents with an execution history of playbook runs.
800-171 3.8.7
Control the use of removable media on system components. ARRTECH: device control by device class, vendor, product or serial number, with a manager approval option.
800-171 3.14.6
Monitor organizational systems to detect attacks and indicators of potential attacks. ARRTECH: classified events carry MITRE ATT&CK tactic and technique columns.
Questions
Does ARRTECH make us 800-171 compliant?
No product can. DoD enforces 800-171 Rev. 2 through self-assessments and select government-led assessments of your system.
Does the SIEM come into scope?
Yes. Under CMMC, a SIEM is a Security Protection Asset, and a store of CUI content is a CUI Asset.
Can our assessor check the logs without ARRTECH?
Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.
Is there a ready 800-171 report?
No ready report is named. A saved query becomes a report, on a schedule, by email or as PDF.
Sources
Guide
What is NIST 800-171?
A NIST publication that sets the security requirements for protecting controlled unclassified information in contractor systems.
What is CUI?
Controlled unclassified information: government information that needs protection but is not classified.
Why Rev. 2 and not Rev. 3?
NIST published Rev. 3 in May 2024. DoD still holds contractors to Rev. 2 by class deviation.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.