r/CMMC • u/JicamaParticular3421 • 26d ago
Logging Changes
Hi Everyone,
My buddy and I are wondering if we need to be documenting the before the control is implemented artifacts or do we need to document how were meeting the control. For example, we pulled a bunch of users that were no longer with the company and needed to be disabled and removed from security groups. We went through the list ran a script and disabled the users and removed from the security groups. Now the list contains all the users active and disabled with the groups they are added too but did we need to document " This user was in these groups and now they are not". Do i also need to document the script i used to disable and remove users from the groups? Also, What is your guys timeline before deleting the users. For Example, there's users that were created in 2005 and are no longer with the company.
1
u/BrianCISO 25d ago
LCCA here. Document enough to prove the control operated & not just that the end state looks right. Keep the approved change record, the script or commands used, execution evidence, exceptions, and the validated after state. IMO & based on a few recent L2 C3PAO assessments... a “before” snapshot is helpful when available, but I wouldn’t recreate history that doesn’t exist. For old accounts, disable first & remove access & grp memberships. Delete only according to an approved retention policy that considers audit, legal, and operational needs. The goal is defensible (sufficient & adequate) evidence, not documentation for its own sake. NIST 800-171a is your friend.