💼 AU-11 Audit Record Retention (L)(M)(H)
- ID:
/frameworks/fedramp-high-security-controls/au/11
Description
Retain audit records for [FedRAMP Assignment: a time period in compliance with M-21-31] to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements.
AU-11 Additional FedRAMP Requirements and Guidance:
Guidance: The service provider is encouraged to align with M-21-31 where possible
Requirement: The service provider retains audit records on-line for at least ninety (90) days and further preserves audit records off-line for a period that is in accordance with NARA requirements.
Requirement: The service provider must support Agency requirements to comply with M-21-31
Similar
- Sections
/frameworks/nist-sp-800-53-r5/au/11
- Internal
- ID:
dec-c-ec0e32b7
- ID:
Similar Sections (Take Policies From)
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 NIST SP 800-53 Revision 5 → 💼 AU-11 Audit Record Retention | 1 | no data |
Similar Sections (Give Policies To)
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 FedRAMP Low Security Controls → 💼 AU-11 Audit Record Retention (L)(M)(H) | 18 | no data | |||
| 💼 FedRAMP Moderate Security Controls → 💼 AU-11 Audit Record Retention (L)(M)(H) | 18 | no data |
Sub Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|
Policies (18)
Internal Rules
| Rule | Policies | Flags |
|---|---|---|
| ✉️ dec-x-0c82d775 | 1 | |
| ✉️ dec-x-9b79d91f | 1 | |
| ✉️ dec-x-9c041667 | 1 | |
| ✉️ dec-x-20c9ef83 | 1 | |
| ✉️ dec-x-24bba483 | 1 | |
| ✉️ dec-x-89d5ed7a | 1 | |
| ✉️ dec-x-611eaa35 | 1 | |
| ✉️ dec-x-1518c16e | 1 | |
| ✉️ dec-x-79579ed7 | 1 | |
| ✉️ dec-x-9002886f | 1 | |
| ✉️ dec-x-b1e1a494 | 1 | |
| ✉️ dec-x-b2ce0ca1 | 1 | |
| ✉️ dec-x-c397d3ca | 2 | |
| ✉️ dec-x-db1b7a1b | 1 | |
| ✉️ dec-x-dc359e59 | 1 | |
| ✉️ dec-x-e0014333 | 2 |