Logit.io
Solutions

CMMC Solution For Small & Medium Sized Enterprises

Logit.io can be leveraged to accelerate compliance with CMMC's auditing and accountability controls

observability stack
Ingest
Correlate
Visualize
Act
Logs
Logstash · OpenSearch
12.4k/s
Metrics
Prometheus · Grafana
10k series
APM
OTLP · traces
p95 84ms
--:--:-- INFO request.completed duration_ms=42 route="/api/v1/orders"
--:--:-- WARN latency.spike service=checkout p95=820ms threshold=500ms
--:--:-- INFO trace.exported spans=128 backend=jaeger status="ok"
--:--:-- INFO metric.scrape target=prometheus job=k8s-pods samples=8421
--:--:-- INFO log.shipped bytes=184032 index=logs-prod
--:--:-- WARN auth.failure ip=203.0.113.42 attempts=3 action=rate_limit
--:--:-- INFO alert.routed severity=high channel="#incidents" dedupe=on
--:--:-- INFO dashboard.refresh uid=ops-overview panels=14 cache=hit
--:--:-- ERROR disk.pressure node=worker-3 usage=92% reclaim=started
--:--:-- INFO pipeline.batch size=2048 lag_ms=18 status=healthy
--:--:-- WARN queue.backpressure topic=ingest depth=1200
--:--:-- INFO otel.export endpoint=collector.svc spans_ok=512
--:--:-- INFO search.query hits=1284 took_ms=37 index=logs-*
--:--:-- INFO retention.policy applied hot=14d warm=30d
--:--:-- WARN tls.cert.expiring host=ingest.logit.io days=12
--:--:-- INFO ha.failover check region=eu-west status=ready
--:--:-- INFO request.completed duration_ms=42 route="/api/v1/orders"
--:--:-- WARN latency.spike service=checkout p95=820ms threshold=500ms
--:--:-- INFO trace.exported spans=128 backend=jaeger status="ok"
--:--:-- INFO metric.scrape target=prometheus job=k8s-pods samples=8421
--:--:-- INFO log.shipped bytes=184032 index=logs-prod
--:--:-- WARN auth.failure ip=203.0.113.42 attempts=3 action=rate_limit
--:--:-- INFO alert.routed severity=high channel="#incidents" dedupe=on
--:--:-- INFO dashboard.refresh uid=ops-overview panels=14 cache=hit
--:--:-- ERROR disk.pressure node=worker-3 usage=92% reclaim=started
--:--:-- INFO pipeline.batch size=2048 lag_ms=18 status=healthy
--:--:-- WARN queue.backpressure topic=ingest depth=1200
--:--:-- INFO otel.export endpoint=collector.svc spans_ok=512
--:--:-- INFO search.query hits=1284 took_ms=37 index=logs-*
--:--:-- INFO retention.policy applied hot=14d warm=30d
--:--:-- WARN tls.cert.expiring host=ingest.logit.io days=12
--:--:-- INFO ha.failover check region=eu-west status=ready
+ one managed platform
+ peak overage protection
! bundle up to 30% off

Trusted by engineering teams worldwide

Maersk
Murphy
Ringier
GDS
Guesty
HackerRank
Equal Experts
DevEx
Digitale Medier
xneelo
CAA
Pivotal
Robomed Network
Neoway
Gomo Learning
Department for BEIS
IBM
Broad Institute
The Honest Company
Traels
De Banke
Dofinity
BioCatch
Kainos
Youredi
Flux Music
Goji
Ving
HypSports
Boston Logic
Double Jump

Logit.io allows you to review all events and audit logs while preventing unauthorised access through our security functions and role-based access controls (RBAC). Use Logit.io to create alerts to inform key users when logging (audit log) processes fail and require further analysis.

Improve your CMMC readiness by harnessing the power of observability and use Logit.io to comply with the following CMMC ID numbers AU.L2-3.3.1, AU.L2-3.3.2, AU.L2-3.3.3, AU.L2-3.3.4, AU.L2-3.3.5 ,AU.L2-3.3.6 ,AU.L2-3.3.8 and AU.L2-3.3.9.

You can take advantage of our 14-day free trial or schedule a call below to speak with a compliance expert about meeting your logging and auditing criteria for CMMC today with Logit.io.

CMMC Framework Overview

In order to bid on United States Department of Defence (DoD) contracts, contractors must conduct CMMC assessments and follow the compliance checklist relevant to how they handle sensitive data.

In addition to the NIST SP 800-171 DoD Assessment Methodology, the FAR clause 52.204-21, and the DFARS clause 252.204-7012, the CMMC builds upon the basic safeguarding requirements established by NIST SP 800-171.

In order to achieve CMMC compliance, controlling CUI, also known as Controlled Unclassified Information, is a major challenge. An organization can often only determine what constitutes CUI and what steps need to be taken to protect it through self-assessment.

As your organization begins an internal audit to determine which level of CMMC it needs to meet, it may be necessary to bring onboard CMMC self-assessment tools to minimize your workload.

pipeline
Ingest
Parse
Index
Query
+streams normalized · schema applied
output ready for search, alerts, and dashboards

CMMC for SMEs

According to CMMC, the event logs generated by system users should be logged so that users can be held accountable for their actions.

Logs generated by your system should be correlated within reporting dashboards so that unlawful, unauthorized, suspicious, or unusual activity cannot go unnoticed.

Logit.io provides a better value alternative to the many reporting suites priced aiming solely towards large enterprises. Logit.io allows SMEs to easily create compliance reports in our fully hosted on-demand analysis dashboards.

stream
--:--:-- INFO request.completed duration_ms=42 route="/api/v1/orders"
--:--:-- WARN latency.spike service=checkout p95=820ms threshold=500ms
--:--:-- INFO trace.exported spans=128 backend=jaeger status="ok"
--:--:-- INFO metric.scrape target=prometheus job=k8s-pods samples=8421
--:--:-- INFO log.shipped bytes=184032 index=logs-prod
--:--:-- WARN auth.failure ip=203.0.113.42 attempts=3 action=rate_limit
--:--:-- INFO alert.routed severity=high channel="#incidents" dedupe=on
--:--:-- INFO dashboard.refresh uid=ops-overview panels=14 cache=hit
--:--:-- ERROR disk.pressure node=worker-3 usage=92% reclaim=started
--:--:-- INFO pipeline.batch size=2048 lag_ms=18 status=healthy
--:--:-- WARN queue.backpressure topic=ingest depth=1200
--:--:-- INFO otel.export endpoint=collector.svc spans_ok=512
--:--:-- INFO search.query hits=1284 took_ms=37 index=logs-*
--:--:-- INFO retention.policy applied hot=14d warm=30d
--:--:-- WARN tls.cert.expiring host=ingest.logit.io days=12
--:--:-- INFO ha.failover check region=eu-west status=ready
--:--:-- INFO request.completed duration_ms=42 route="/api/v1/orders"
--:--:-- WARN latency.spike service=checkout p95=820ms threshold=500ms
--:--:-- INFO trace.exported spans=128 backend=jaeger status="ok"
--:--:-- INFO metric.scrape target=prometheus job=k8s-pods samples=8421
--:--:-- INFO log.shipped bytes=184032 index=logs-prod
--:--:-- WARN auth.failure ip=203.0.113.42 attempts=3 action=rate_limit
--:--:-- INFO alert.routed severity=high channel="#incidents" dedupe=on
--:--:-- INFO dashboard.refresh uid=ops-overview panels=14 cache=hit
--:--:-- ERROR disk.pressure node=worker-3 usage=92% reclaim=started
--:--:-- INFO pipeline.batch size=2048 lag_ms=18 status=healthy
--:--:-- WARN queue.backpressure topic=ingest depth=1200
--:--:-- INFO otel.export endpoint=collector.svc spans_ok=512
--:--:-- INFO search.query hits=1284 took_ms=37 index=logs-*
--:--:-- INFO retention.policy applied hot=14d warm=30d
--:--:-- WARN tls.cert.expiring host=ingest.logit.io days=12
--:--:-- INFO ha.failover check region=eu-west status=ready

Logit.io's CMMC Logging Solution

With Logit.io's CMMC solution, you can meet ten key controls across multiple levels of CMMC, providing tremendous value to organizations that need to meet their own level 3 compliance requirements, but also need to audit a trusted vendor at a lower level, such as level 1. Both of these use cases can be handled by the Logit.io platform seamlessly, which saves administrators and auditors time.

Use Logit.io to meet CMMC requirements, follow audit logging best practices, and ensure that role-based access controls are always in place so you can simplify the certification process.

In order to meet CMMC guidelines, you should use as few distributed tools as possible so that your compliance team does not have to audit additional tools to ensure they adhere to the same security standards.

The Logit.io platform can certainly help you get closer to being able to compete on DOD contracts again, even if no single tool can manage your CMMC compliance journey completely.

shell
$
logit trace export --protocol=otlp --backend=jaeger
→ distributed spans indexed · p99=84ms

Scalability & Affordability

For hundreds of thousands of DoD contractors, CMMC, also known as Cybersecurity Maturity Model, has proven to be a time-consuming and costly process. With requirements ever-changing, it is wise to consider selecting a tool that is highly scalable and strives to meet the increasingly complex requirements of data management and security.

As your data grows or the CMMC changes its audit log requirements over the next few years, our platform strives to be highly scalable and highly available to accommodate these changes. You can rely on our platform to be available at all times thanks to high availability open source software and 99.999% availability SLAs.

In contrast to the estimated cost of CMMC compliance at approximately $5,000 for level 1 certification (with the cost increasing dramatically for subsequent levels), Logit.io log management plans start from $25/mo, with a 14-day free trial and 20% savings on annual billing.

metrics
latency
throughput
errors
p95 latency 84ms · ingest 12.4k/s · error rate 0.08%

Demonstrate CMMC Compliance With The Following Controls:

  • AU.L2-3.3.1
  • AU.L2-3.3.2
  • AU.L2-3.3.3
  • AU.L2-3.3.4
  • AU.L2-3.3.5
  • AU.L2-3.3.6
  • AU.L2-3.3.8
  • AU.L2-3.3.9
  • alerts
    1
    Detect
    2
    Enrich
    3
    Route
    4
    Notify
    ! anomaly detected · checkout p95 > 500ms
    → context attached · service map · recent deploy
    → routed to #incidents · ack in 12s

    Companies Feel The Difference When They Use Logit.io

    Internally, Logit.io has made it easier for us to provide better support for our customers, since finding individual messages based on various data in the payload has become easier.

    At Youredi, pretty much everyone from our technical support teams through to our professional services teams uses Logit.io.

    Youredi

    Mats von Weissenberg

    CTO @ Youredi

    Start your 14-day free trial

    No credit card required. Managed OpenSearch, Prometheus, and Grafana from $25/mo.