Skip to main content

💼 AU Audit And Accountability

  • Contextual name: 💼 AU Audit And Accountability
  • ID: /frameworks/nist-sp-800-53-r5/au
  • Located in: 💼 NIST SP 800-53 Revision 5

Description​

Empty...

Similar​

  • Internal
    • ID: dec-b-4e3cc3c6

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
💼 AU-1 Policy and Procedures
💼 AU-2 Event Logging417
    💼 AU-2(1) Event Logging _ Compilation of Audit Records from Multiple Sources
    💼 AU-2(2) Event Logging _ Selection of Audit Events by Component
    💼 AU-2(3) Event Logging _ Reviews and Updates
    💼 AU-2(4) Event Logging _ Privileged Functions
💼 AU-3 Content of Audit Records314
    💼 AU-3(1) Content of Audit Records _ Additional Audit Information1314
    💼 AU-3(2) Content of Audit Records _ Centralized Management of Planned Audit Record Content
    💼 AU-3(3) Content of Audit Records _ Limit Personally Identifiable Information Elements
💼 AU-4 Audit Log Storage Capacity1
    💼 AU-4(1) Audit Log Storage Capacity _ Transfer to Alternate Storage
💼 AU-5 Response to Audit Logging Process Failures5
    💼 AU-5(1) Response to Audit Logging Process Failures _ Storage Capacity Warning
    💼 AU-5(2) Response to Audit Logging Process Failures _ Real-time Alerts
    💼 AU-5(3) Response to Audit Logging Process Failures _ Configurable Traffic Volume Thresholds
    💼 AU-5(4) Response to Audit Logging Process Failures _ Shutdown on Failure
    💼 AU-5(5) Response to Audit Logging Process Failures _ Alternate Audit Logging Capability
💼 AU-6 Audit Record Review, Analysis, and Reporting102
    💼 AU-6(1) Audit Record Review, Analysis, and Reporting _ Automated Process Integration11
    💼 AU-6(2) Audit Record Review, Analysis, and Reporting _ Automated Security Alerts
    💼 AU-6(3) Audit Record Review, Analysis, and Reporting _ Correlate Audit Record Repositories8
    💼 AU-6(4) Audit Record Review, Analysis, and Reporting _ Central Review and Analysis8
    💼 AU-6(5) Audit Record Review, Analysis, and Reporting _ Integrated Analysis of Audit Records
    💼 AU-6(6) Audit Record Review, Analysis, and Reporting _ Correlation with Physical Monitoring
    💼 AU-6(7) Audit Record Review, Analysis, and Reporting _ Permitted Actions
    💼 AU-6(8) Audit Record Review, Analysis, and Reporting _ Full Text Analysis of Privileged Commands
    💼 AU-6(9) Audit Record Review, Analysis, and Reporting _ Correlation with Information from Nontechnical Sources
    💼 AU-6(10) Audit Record Review, Analysis, and Reporting _ Audit Level Adjustment
💼 AU-7 Audit Record Reduction and Report Generation217
    💼 AU-7(1) Audit Record Reduction and Report Generation _ Automatic Processing11
    💼 AU-7(2) Audit Record Reduction and Report Generation _ Automatic Sort and Search
💼 AU-8 Time Stamps2
    💼 AU-8(1) Time Stamps _ Synchronization with Authoritative Time Source
    💼 AU-8(2) Time Stamps _ Secondary Authoritative Time Source
💼 AU-9 Protection of Audit Information72
    💼 AU-9(1) Protection of Audit Information _ Hardware Write-once Media
    💼 AU-9(2) Protection of Audit Information _ Store on Separate Physical Systems or Components
    💼 AU-9(3) Protection of Audit Information _ Cryptographic Protection
    💼 AU-9(4) Protection of Audit Information _ Access by Subset of Privileged Users22
    💼 AU-9(5) Protection of Audit Information _ Dual Authorization
    💼 AU-9(6) Protection of Audit Information _ Read-only Access
    💼 AU-9(7) Protection of Audit Information _ Store on Component with Different Operating System
💼 AU-10 Non-repudiation57
    💼 AU-10(1) Non-repudiation _ Association of Identities
    💼 AU-10(2) Non-repudiation _ Validate Binding of Information Producer Identity
    💼 AU-10(3) Non-repudiation _ Chain of Custody
    💼 AU-10(4) Non-repudiation _ Validate Binding of Information Reviewer Identity
    💼 AU-10(5) Non-repudiation _ Digital Signatures
💼 AU-11 Audit Record Retention1
    💼 AU-11(1) Audit Record Retention _ Long-term Retrieval Capability
💼 AU-12 Audit Record Generation44765
    💼 AU-12(1) Audit Record Generation _ System-wide and Time-correlated Audit Trail
    💼 AU-12(2) Audit Record Generation _ Standardized Formats
    💼 AU-12(3) Audit Record Generation _ Changes by Authorized Individuals
    💼 AU-12(4) Audit Record Generation _ Query Parameter Audits of Personally Identifiable Information
💼 AU-13 Monitoring for Information Disclosure3
    💼 AU-13(1) Monitoring for Information Disclosure _ Use of Automated Tools
    💼 AU-13(2) Monitoring for Information Disclosure _ Review of Monitored Sites
    💼 AU-13(3) Monitoring for Information Disclosure _ Unauthorized Replication of Information
💼 AU-14 Session Audit3
    💼 AU-14(1) Session Audit _ System Start-up1
    💼 AU-14(2) Session Audit _ Capture and Record Content
    💼 AU-14(3) Session Audit _ Remote Viewing and Listening
💼 AU-15 Alternate Audit Logging Capability
💼 AU-16 Cross-organizational Audit Logging3
    💼 AU-16(1) Cross-organizational Audit Logging _ Identity Preservation
    💼 AU-16(2) Cross-organizational Audit Logging _ Sharing of Audit Information
    💼 AU-16(3) Cross-organizational Audit Logging _ Disassociability