How AWS Audit Manager Maps CMMC Evidence to ISO 27001 (AU.L2-3.3.6)

How AWS Audit Manager Maps CMMC Evidence to ISO 27001 (AU.L2-3.3.6)

Use an AWS Audit Manager CMMC ISO 27001 evidence crosswalk to reuse log-analysis evidence across CMMC, ISO 27001, SOC 2, and NIST CSF.

LakeRidge Team
July 18, 2026
9 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

An AWS Audit Manager CMMC ISO 27001 evidence crosswalk for AU.L2-3.3.6 should connect one tested capability—reducing high-volume audit data and generating on-demand reports—to ISO 27001:2022 Annex A controls 8.15 and 8.16, SOC 2 CC7.2 and CC7.3, and NIST CSF 2.0 Detect outcomes such as DE.CM-01 and DE.AE-02. AWS Audit Manager can organize the resulting evidence by assessment and control, but the underlying proof must come from services that actually query, filter, preserve, and report on logs, such as AWS CloudTrail Lake, Amazon CloudWatch Logs Insights, Amazon Security Lake, and a SIEM. For an external assessment, the strongest package demonstrates both the technical capability and a repeatable reviewer process.

Why does an AWS Audit Manager CMMC ISO 27001 evidence crosswalk save audit cycles?

CMMC 2.0 Level 2 practice AU.L2-3.3.6, derived from NIST SP 800-171 Rev. 2 requirement 3.3.6, requires an organization to provide audit-record reduction and report-generation capabilities that support on-demand analysis and reporting. The practice is not satisfied merely because raw AWS logs exist. An assessor will want evidence that personnel can turn large log volumes into relevant, reviewable information without modifying the original records.

That objective overlaps materially with ISO 27001 logging and monitoring expectations, SOC 2 monitoring and event-evaluation criteria, and NIST CSF detection outcomes. Rather than collecting four separate screenshots of the same CloudTrail Lake query or CloudWatch dashboard, an internal auditor can build a common evidence set, then map each item to the distinct language and emphasis of each framework.

The audit-cycle savings come from separating common technical evidence from framework-specific conclusions. For example, a saved CloudTrail Lake query that excludes approved backup activity, filters for privileged IAM changes, and retains a defined time window can support all four frameworks. The CMMC narrative explains audit-record reduction and on-demand reporting; the ISO 27001 narrative addresses logging and monitoring; the SOC 2 narrative explains event identification and evaluation; and the NIST CSF narrative explains continuous monitoring and analysis.

For your workpapers, avoid representing this as a one-to-one equivalence. An AWS Audit Manager CMMC ISO 27001 evidence crosswalk is an evidence-reuse method, not a claim that certification in one framework automatically satisfies another.

How does AU.L2-3.3.6 map to ISO 27001, SOC 2, and NIST CSF?

Framework requirement Comparable requirement or outcome What the overlap supports AWS evidence to retain
CMMC 2.0 L2 AU.L2-3.3.6
Provide audit record reduction and report generation to support on-demand analysis and reporting.
ISO/IEC 27001:2022 Annex A 8.15
Logging
Annex A 8.16
Monitoring activities
Logs are produced, protected as relevant, reviewed or monitored, and made useful for detecting abnormal activity. Reduced views and reports demonstrate that logging is operationally usable. CloudTrail Lake saved queries; CloudWatch Logs Insights saved queries; dashboard exports; report samples; procedures defining who can request and review reports.
CMMC 2.0 L2 AU.L2-3.3.6
On-demand reduction and reporting
SOC 2 CC7.2
Monitors system components and anomalous events
SOC 2 CC7.3
Evaluates security events to determine whether they are incidents
Relevant events are identified from monitoring data and evaluated promptly. The report must help reviewers distinguish actionable events from expected operational noise. Security Hub findings views; SIEM correlation-rule output; CloudWatch alarms; incident tickets showing analyst review of a generated report.
CMMC 2.0 L2 AU.L2-3.3.6
Audit reduction and reporting capability
NIST CSF 2.0 DE.CM-01
Networks and network services are monitored
DE.CM-09
Computing hardware and software are monitored
DE.AE-02
Potentially adverse events are analyzed
Telemetry is monitored and analyzed so potential adverse events can be identified and understood. Reporting provides a usable output of that analysis. CloudWatch dashboards; Amazon Security Lake data-source configuration; Amazon Athena query history; detection-engineering documentation; analyst reports.
CMMC 2.0 L2 AU.L2-3.3.6
Preserve original records while reducing views
ISO/IEC 27001:2022 Annex A 5.33
Protection of records
SOC 2 CC6.1
Logical access security controls
Reduction should create a derived view or report, not alter the original audit trail. Access to raw logs and report-generation functions should be controlled. S3 Object Lock or log-archive retention configuration; CloudTrail log-file validation settings; IAM policies for query and log-access roles; AWS Config evidence.

The most useful cross-framework design is to preserve immutable or protected raw records in a log archive while allowing authorized analysts to query copies or centralized data stores. In AWS, that often means organization-level AWS CloudTrail trails sending logs to a restricted Amazon S3 bucket, with CloudTrail Lake, CloudWatch Logs Insights, Amazon OpenSearch Service, Amazon Security Lake, or an external SIEM providing the reduction and reporting layer.

Where do the mappings not align?

The biggest gotcha is that ISO 27001 Annex A 8.15 and 8.16 do not state the CMMC requirement in the same prescriptive terms. ISO 27001 expects appropriate logging and monitoring, but it does not expressly require an “audit-record reduction capability” or “on-demand report generation” using the language of AU.L2-3.3.6. Your Statement of Applicability, risk treatment, and operating procedures must explain why your selected controls and evidence adequately address the organization’s logging and monitoring risks.

  • CMMC requires both capabilities. A dashboard alone may support reporting, but it may not prove deliberate reduction of raw records. Conversely, a saved query may reduce data but not show that personnel can generate a succinct report on demand.
  • SOC 2 is criteria- and system-description-dependent. CC7.2 and CC7.3 often support the mapping, but the service organization’s commitments, system boundaries, and control wording determine the exact evidence needed.
  • NIST CSF is outcome-oriented. CSF 2.0 can describe the desired monitoring and analysis outcome, but it does not by itself prescribe a particular report format, frequency, retention period, or AWS service.
  • AWS Audit Manager does not reduce logs. It collects and organizes evidence. Do not present an Audit Manager assessment report as proof that raw logs were filtered, analyzed, or investigated unless linked technical evidence demonstrates those actions.
  • Filtering cannot conceal relevant activity. Excluding routine nightly backups may be reasonable, but the exclusion must be documented, approved, and periodically reviewed. Filtering rules that remove failed backups, privilege changes, or abnormal data-transfer events could undermine the control.

External assessors commonly test this distinction by asking an analyst to produce a targeted report during the assessment period. Prepare for questions such as: “Show failed console logins for the prior seven days,” “Show production security-group changes made outside the change window,” or “Show all access-key creation events and the related investigation status.”

How do you build one evidence package that satisfies all four frameworks?

Build a primary evidence package around the two CMMC objectives: an audit-record reduction capability and an on-demand report-generation capability. Then use AWS Audit Manager to attach the evidence to the applicable CMMC, ISO 27001, SOC 2, and custom NIST CSF assessments. The same artifact can be referenced repeatedly, but each control should have its own concise rationale and test result.

  1. Document the source and preservation layer. Retain the organization-level CloudTrail configuration, S3 log-archive bucket policy, retention settings, CloudTrail log-file validation status, and access-control evidence. Establish that the original audit records remain available and protected.
  2. Capture the reduction mechanism. Export saved CloudTrail Lake or CloudWatch Logs Insights queries that remove documented benign operational noise while preserving security-relevant fields. Include the query name, owner, approval date, data source, and intended use case.
  3. Capture the reporting mechanism. Retain a generated PDF, CSV, dashboard export, or SIEM report produced from the reduced data. The report should include the reporting period, query or rule identifier, generation timestamp, and analyst or automation owner.
  4. Prove on-demand operation. Include a ticket, investigation record, or tabletop exercise showing that an authorized person requested and received a relevant report without waiting for a scheduled monthly process.
  5. Write framework-specific annotations. For CMMC, explicitly identify reduction and reporting. For ISO, explain logging and monitoring coverage. For SOC 2, connect the output to anomaly identification and event evaluation. For CSF, connect it to monitoring and adverse-event analysis.

A defensible sample configuration might use CloudTrail Lake event data stores for management events, a saved query named PrivilegedChanges_7Day_Review, and a CloudWatch dashboard that presents failed authentication trends, IAM policy changes, and Security Hub findings. The query output should retain event time, principal, source IP, API name, affected resource, error code, and region while excluding only documented low-risk events.

SELECT eventTime, userIdentity.arn, sourceIPAddress, eventName,
       awsRegion, errorCode, resources
FROM   event_data_store_ID
WHERE  eventTime >= '2026-07-01 00:00:00'
  AND  eventName IN ('CreateUser', 'AttachUserPolicy',
                     'PutUserPolicy', 'AuthorizeSecurityGroupIngress')
  AND  errorCode IS NULL
ORDER BY eventTime DESC;

For the internal audit file, preserve the query logic and a representative output, not just a screenshot of a green dashboard. Screenshots are useful corroboration, but exported configuration, access-control evidence, and a tested report provide stronger support for an assessor’s re-performance procedures.

Which AWS tools automate the mapping and evidence collection?

A practical AWS Audit Manager CMMC ISO 27001 evidence crosswalk uses Audit Manager as the evidence register and AWS logging tools as the operational proof. Start with AWS Audit Manager framework assessments where applicable, then create custom controls when the supplied framework control language does not capture your exact AU.L2-3.3.6 implementation. Link evidence folders or automated evidence sources to the control objectives, and maintain a traceable mapping matrix outside the tool if your assessment methodology requires reviewer conclusions.

  • AWS Audit Manager: Collects AWS-generated evidence, stores manual evidence, organizes assessments, and produces assessment reports for review.
  • AWS CloudTrail and CloudTrail Lake: Preserve management-event history and enable SQL-based, repeatable reduction queries across selected time periods.
  • Amazon CloudWatch Logs Insights: Supports interactive query-based reduction and dashboards for operational reporting where relevant logs are delivered to CloudWatch Logs.
  • Amazon Security Lake and Amazon Athena: Centralize security telemetry and support standardized analysis across AWS and supported third-party sources.
  • AWS Security Hub and Amazon GuardDuty: Add prioritized findings that help show the organization is converting telemetry into security-relevant review activity.
  • AWS Config: Provides configuration-history evidence that supports the integrity of logging, retention, and access-control settings.

Before external assessment, run one controlled re-performance exercise: have a reviewer request a defined security report, generate it from the approved reduced-log query, verify the raw source remains intact, and attach the resulting artifacts and review record to the relevant AWS Audit Manager assessment.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.