Skip to main content

💼 AU-9 Protection of Audit Information

  • Contextual name: 💼 AU-9 Protection of Audit Information
  • ID: /frameworks/nist-sp-800-53-r5/au/09
  • Located in: 💼 AU Audit And Accountability

Description

a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and b. Alert [Assignment: organization-defined personnel or roles] upon detection of unauthorized access, modification, or deletion of audit information.

Similar

  • Sections
    • /frameworks/aws-fsbp-v1.0.0/cloudtrail/02
    • /frameworks/aws-fsbp-v1.0.0/cloudtrail/04
  • Internal
    • ID: dec-c-b292bd51

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlags
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [CloudTrail.2] CloudTrail should have encryption at-rest enabled1
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [CloudTrail.4] CloudTrail log file validation should be enabled11

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlags
💼 FedRAMP High Security Controls → 💼 AU-9 Protection of Audit Information (L)(M)(H)3810
💼 FedRAMP Low Security Controls → 💼 AU-9 Protection of Audit Information (L)(M)(H)10
💼 NIST CSF v2.0 → 💼 PR.DS-10: The confidentiality, integrity, and availability of data-in-use are protected111

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags
💼 AU-9(1) Protection of Audit Information _ Hardware Write-once Media
💼 AU-9(2) Protection of Audit Information _ Store on Separate Physical Systems or Components
💼 AU-9(3) Protection of Audit Information _ Cryptographic Protection
💼 AU-9(4) Protection of Audit Information _ Access by Subset of Privileged Users22
💼 AU-9(5) Protection of Audit Information _ Dual Authorization
💼 AU-9(6) Protection of Audit Information _ Read-only Access
💼 AU-9(7) Protection of Audit Information _ Store on Component with Different Operating System

Policies (2)

PolicyLogic CountFlags
📝 AWS CloudTrail is not encrypted with KMS CMK 🟢1🟢 x6
📝 AWS CloudTrail Log File Validation is not enabled 🟢1🟢 x6