Audit Record Reduction and Report Generation gives your analysts a way to make sense of the raw audit records. Audit Record Generation (03.03.03) produces the records and Audit Record Review, Analysis, and Reporting (03.03.05) requires you to use them, but the volume of raw logs is often unusable without help. Audit Record Reduction and Report Generation (03.03.06) requires a capability that reduces and reports on audit records to support review, analysis, reporting requirements, and after-the-fact investigations, while preserving the original content and time ordering of the records. Per the NIST discussion, reduction organizes collected audit information into a summary format that is more meaningful to analysts, and the reduction and reporting capability does not have to come from the same system that conducts the auditing.
A common difficulty with this requirement is confusing the source records with the reporting layer. The reduction and report generation capability works on top of the records, and it must not alter the originals. Two of the objectives specifically require preserving the original content and the original time ordering, so a reduction tool that reorders or rewrites records fails the requirement even if its reports look useful.
Where things stand for companies facing the transition from NIST 800-171 R2 to R3:
The following is reproduced verbatim from NIST 800-171 R3, requirement 03.03.06 Audit Record Reduction and Report Generation. Only the formatting has been adjusted for readability. This requirement has two (2) lettered parts:
The source control is AU-07 from NIST 800-53. There are no Organization-Defined Parameters (ODPs). Per the NIST discussion, audit record reduction and report generation occur after audit record generation in 03.03.03, a reduction capability can include modern data mining techniques with advanced filters to identify anomalous behavior, and the time ordering of records can be a significant issue if the granularity of the time stamp is insufficient. You can read the requirement directly at NIST 800-171 R3, 03.03.06 (p. 25).
None (0). Requirement 03.03.06 contains no bracketed assignment, so there is no organization-defined value to select and nothing for the DoD to specify. The requirement applies as written.
Your System Security Plan (SSP) narrative for 03.03.06 therefore records how the requirement is implemented rather than a parameter you chose.
NIST 800-171A R3 breaks 03.03.06 into six (6) determination statements, and it has no Organization-Defined Parameters (ODPs). These AOs are:
Part a becomes four (4) objectives, one for each thing the capability must support, and part b becomes two, one for original content and one for original time ordering. An assessor checks each, so a reporting tool that supports analysis but not after-the-fact investigation, or that preserves content but reorders records, leaves objectives open. The full guidance on assessment methods and objects, is in NIST 800-171A R3, 03.03.06 (p. 29).
Examine: audit and accountability policy and procedures; procedures for audit record reduction and report generation; audit record reduction, review, analysis, and reporting tools; system audit records; system design documentation; system configuration settings; system security plan.
Interview: personnel with audit record reduction and report generation responsibilities; personnel with information security responsibilities.
Test: mechanisms for supporting audit record reduction and report generation capability.
03.03.06 maps from NIST 800-171 R2 requirement 3.3.6 (provide audit record reduction and report generation to support on-demand analysis and reporting):
Mapped against the six (6) AOs, three (3) are direct (minimal effort) and three (3) are indirect (moderate effort), with no net-new AOs and none with no mapping. The reduction and report generation capability carries forward, but R3 makes explicit that the capability must support after-the-fact investigations and must preserve original content and time ordering. Verify your tooling meets all four support objectives and both preservation objectives rather than assuming a reporting feature covers them.
Source Control in NIST 800-53 R5:
Secure Controls Framework (SCF) Crosswalk
Organizations running a single control set across multiple frameworks can satisfy 03.03.06 through the following SCF controls:
The crosswalks from NIST 800-171 R3 and NIST 800-171A R3 to the SCF are available at no cost through the SCF Set Theory Relationship Mapping (STRM): https://securecontrolsframework.com/start-here/set-theory-relationship-mapping-strm. The STRM also carries the relationship type for each mapping (Equal, Subset Of, Intersects With), which tells you whether an SCF control fully satisfies the requirement or only part of it. Mapping above taken from SCF 2026.3.
The following are issues teams may encounter rather than certainties. They are about preservation and the full scope of the capability, each of which needs documented evidence of due diligence and due care such as policies, standards, procedures, and configuration screenshots:
Reasonable objective evidence for an assessment is often subjective. The following examples of evidence to address NIST 800-171 R3 03.03.06 are sourced from the SCF Evidence Request List (ERL), available at https://securecontrolsframework.com/free-content/scf-download. These ERL artifacts are mapped to NIST 800-171 R3 03.03.06 through SCF controls. They establish a starting point for discussions on what an organization needs to have for evidence of due diligence and due care to withstand external scrutiny by an assessor or regulator.
Alongside these, keep the System Security Plan (SSP) narrative for 03.03.06.
With three (3) AOs mapping directly and three indirectly, 03.03.06 is a moderate lift focused on capability coverage. A realistic sequence:
How many assessment objectives does NIST 800-171 R3 03.03.06 have? NIST 800-171A R3 breaks 03.03.06 into six (6) assessment objectives. An assessor works through each one separately, so each needs its own evidence.
Which NIST 800-53 R5 control does NIST 800-171 R3 03.03.06 come from? AU-07.
How many Organization-Defined Parameters (ODPs) does NIST 800-171 R3 03.03.06 have? None (0). The requirement contains no bracketed assignment, so there is no organization-defined value and nothing for the DoD to specify.
Where does NIST 800-171 R3 03.03.06 sit in the NIST 800-171 R3 Kill Chain? Phase 11, Situational Awareness (SA). The Kill Chain is a phased model for sequencing R3 implementation, and it assigns this requirement to that phase.
03.03.06 Audit Record Reduction and Report Generation requires a capability that reduces and reports on audit records to support review, analysis, reporting, and after-the-fact investigations, while preserving the original content and time ordering. It maps from R2 3.3.6 with three (3) objectives transitioning directly and three indirectly, and none net new. The recurring problem is a reporting tool that reorders or rewrites records. Confirm the capability covers all four support functions, preserves original content and time ordering, and coordinates with your time stamp granularity.
Authoritative sources:
Authoritative sources:
This guide reproduces U.S. Government text from NIST 800-171 R3 and NIST 800-171A R3. It is educational, not legal or assessment advice. Last reviewed: 2026-09-22.