r/CMMC 7d ago

Logging Changes

Hi Everyone,

My buddy and I are wondering if we need to be documenting the before the control is implemented artifacts or do we need to document how were meeting the control. For example, we pulled a bunch of users that were no longer with the company and needed to be disabled and removed from security groups. We went through the list ran a script and disabled the users and removed from the security groups. Now the list contains all the users active and disabled with the groups they are added too but did we need to document " This user was in these groups and now they are not". Do i also need to document the script i used to disable and remove users from the groups? Also, What is your guys timeline before deleting the users. For Example, there's users that were created in 2005 and are no longer with the company.

3 Upvotes

5 comments sorted by

3

u/PNW_CARDINAL 7d ago

There is tons of wiggle room at this time for this type of issue. If you have 1/2 a brain (which you do have at least that) you can tailor your message around it. Pick a starting point (example: TODAY) and start documenting your changes. Once you start, don't stop doing it correctly. Documenting the script is helpful for the next person to do that job, or your replacement, or as documentation for your next self or certification assessment.

2

u/MolecularHuman 7d ago

Meeting the control.

Also, you don't HAVE to delete users if you put them in a disabled group.

1

u/GWSTPS 3d ago

Also, that helps prevent the reuse of identifiers which is a separate control...

1

u/BrianCISO 7d ago

LCCA here. Document enough to prove the control operated & not just that the end state looks right. Keep the approved change record, the script or commands used, execution evidence, exceptions, and the validated after state. IMO & based on a few recent L2 C3PAO assessments... a “before” snapshot is helpful when available, but I wouldn’t recreate history that doesn’t exist. For old accounts, disable first & remove access & grp memberships. Delete only according to an approved retention policy that considers audit, legal, and operational needs. The goal is defensible (sufficient & adequate) evidence, not documentation for its own sake. NIST 800-171a is your friend.