3.3.9 Limit management of audit logging functionality to a subset of privileged users.
Individuals with privileged access to a system and who are also the subject of an audit by that system, may affect the reliability of audit information by inhibiting audit logging activities or modifying audit records. This requirement specifies that privileged access be further defined between audit-related privileges and other privileges, thus limiting the users with audit-related privileges.
Actionable Items: This can be best maintained by using 3rd party security and auditing software. This software must be properly monitored and maintained. Access to this should be reserved for security admins only. Regular reviews and reports can be generated for review and tracking of your system.