CMMC 3.14.6 (System Monitoring): SIEM Evidence & What Assessors Actually Check
Control: NIST SP 800-171 Rev. 2 §3.14.6 · CMMC Practice: SI.L2-3.14.6 · Updated June 2026
Plain-English answer
3.14.6 says: monitor the system — including inbound and outbound traffic — to detect attacks and indicators of potential attacks. The bar isn't "we collect logs." It's "something is actively watching, something raises an alert, and a human responds."
3.14.6 vs. 3.3.1 — the line assessors draw
3.3.1 is create and retain audit records. 3.14.6 is actively detect attacks. You can fully satisfy 3.3.1 by storing logs no one reads — that will fail 3.14.6. The two controls are paired but not redundant.
Control lineage
- CMMC Practice: SI.L2-3.14.6
- NIST 800-171 Rev. 2: §3.14.6 — monitor the system, including inbound and outbound communications traffic, to detect attacks and indicators of potential attacks.
- NIST 800-171A objectives: [a] the system is monitored to detect attacks and indicators of potential attacks; [b] inbound communications traffic is monitored to detect attacks and indicators of potential attacks; [c] outbound communications traffic is monitored to detect attacks and indicators of potential attacks.
What the assessor will EXAMINE
- SIEM (or equivalent) architecture diagram showing all CUI-relevant log sources feeding in.
- Active detection ruleset / use-case catalog (not vendor defaults left untuned).
- Sample alerts from the last 30–90 days with the triage notes attached.
- Network monitoring evidence for both inbound and outbound traffic — outbound is the most-missed half.
- On-call / escalation procedure tying alerts to a named responder.
- SSP narrative for 3.14.6 referencing the SIEM, rules, and response process.
What the assessor will INTERVIEW
- "Walk me through the last alert this SIEM raised." — open the ticket, show the triage, name the responder.
- "How would you know if a CUI workstation started beaconing outbound to an unknown host?" — point to the detection that would fire.
- "Who watches this overnight and on weekends?" — name the SOC or on-call rotation.
What the assessor will TEST
- Verify a representative CUI host is sending logs by searching for it live in the SIEM.
- Sample the detection ruleset for tuning (not just out-of-the-box rules in "report" mode).
- Trace one historical alert from generation → notification → response → closure.
Evidence examples (produce these)
- SIEM data-source inventory: endpoints, servers, firewall, DNS, identity provider, cloud control plane.
- Detection-rule catalog with MITRE ATT&CK coverage notes.
- 5–10 sample alerts (recent) with triage timestamps and responder names.
- Firewall/IDS configuration showing inbound and outbound inspection.
- SOC contract + monthly report (if managed), or on-call rotation if in-house.
- Incident response procedure tying detection to containment.
- SSP §3.14.6 referencing the SIEM, rules, and response.
Platform-specific
- Microsoft GCC High: Microsoft Sentinel with Defender XDR feeds, Entra sign-in logs, and Defender for Cloud alerts — show analytics rules, automation rules, and a triaged incident.
- Google Workspace: Workspace logs → Chronicle SIEM (or Splunk/Sentinel via export), with detections covering Workspace admin actions, OAuth grants, and data exfiltration patterns.
- Athena: SIEM Sync + Live Telemetry auto-correlates SI/AU telemetry to control coverage and surfaces 3.14.6 gaps as evidence requests rather than after-the-fact findings.
Common failure patterns
- "We have logs" — but nothing reads them. Retention ≠ monitoring.
- Inbound monitored, outbound ignored. Objective [c] fails.
- SIEM exists but uses only vendor-default rules in "report" mode, no alerts ever fired.
- Alerts fire but route to a shared inbox no one owns — no responder, no response.
- CUI-handling endpoints aren't actually forwarding logs (assessor searches and the host is silent).
SPRS impact & POA&M
SPRS: not meeting 3.14.6 is a 5-point deduction. POA&M: POA&M eligibility for individual requirements is restricted under CMMC — confirm 3.14.6's eligibility against current rules before assuming it can be deferred.
Assessor-ready summary
You're good on 3.14.6 when CUI-relevant systems are feeding a SIEM, tuned detections fire alerts on both inbound and outbound traffic, a named responder closes them, and the SSP narrates the same picture.
Turn your SIEM into 3.14.6 evidence — not just data retention. Get a monitoring evidence map →
Related: 3.3.1 audit logging · 3.13.11 FIPS crypto · Calculate your SPRS score
Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.