Skip to main content

πŸ’Ό AU-6 Audit Record Review, Analysis, and Reporting

  • Contextual name: πŸ’Ό AU-6 Audit Record Review, Analysis, and Reporting
  • ID: /frameworks/nist-sp-800-53-r5/au/06
  • Located in: πŸ’Ό AU Audit And Accountability

Description​

a. Review and analyze system audit records [Assignment: organization-defined frequency] for indications of [Assignment: organization-defined inappropriate or unusual activity] and the potential impact of the inappropriate or unusual activity; b. Report findings to [Assignment: organization-defined personnel or roles]; and c. Adjust the level of audit record review, analysis, and reporting within the system when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information.

Similar​

  • Internal
    • ID: dec-c-3ce33089

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό AU-6 Audit Record Review, Analysis, and Reporting (L)(M)(H)62126
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό AU-6 Audit Record Review, Analysis, and Reporting (L)(M)(H)23
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό DE.AE-02: Potentially adverse events are analyzed to better understand associated activities26
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό DE.AE-03: Information is correlated from multiple sources26

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό AU-6(1) Audit Record Review, Analysis, and Reporting _ Automated Process Integration11
πŸ’Ό AU-6(2) Audit Record Review, Analysis, and Reporting _ Automated Security Alerts
πŸ’Ό AU-6(3) Audit Record Review, Analysis, and Reporting _ Correlate Audit Record Repositories6
πŸ’Ό AU-6(4) Audit Record Review, Analysis, and Reporting _ Central Review and Analysis6
πŸ’Ό AU-6(5) Audit Record Review, Analysis, and Reporting _ Integrated Analysis of Audit Records
πŸ’Ό AU-6(6) Audit Record Review, Analysis, and Reporting _ Correlation with Physical Monitoring
πŸ’Ό AU-6(7) Audit Record Review, Analysis, and Reporting _ Permitted Actions
πŸ’Ό AU-6(8) Audit Record Review, Analysis, and Reporting _ Full Text Analysis of Privileged Commands
πŸ’Ό AU-6(9) Audit Record Review, Analysis, and Reporting _ Correlation with Information from Nontechnical Sources
πŸ’Ό AU-6(10) Audit Record Review, Analysis, and Reporting _ Audit Level Adjustment