Skip to main content

πŸ’Ό AU-9 Protection of Audit Information

  • Contextual name: πŸ’Ό AU-9 Protection of Audit Information
  • ID: /frameworks/nist-sp-800-53-r5/au/09
  • Located in: πŸ’Ό AU Audit And Accountability

Description​

a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and b. Alert [Assignment: organization-defined personnel or roles] upon detection of unauthorized access, modification, or deletion of audit information.

Similar​

  • Sections
    • /frameworks/aws-fsbp-v1.0.0/cloudtrail/02
    • /frameworks/aws-fsbp-v1.0.0/cloudtrail/04
  • Internal
    • ID: dec-c-b292bd51

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [CloudTrail.2] CloudTrail should have encryption at-rest enabled1
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [CloudTrail.4] CloudTrail log file validation should be enabled11

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό AU-9 Protection of Audit Information (L)(M)(H)3911
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό AU-9 Protection of Audit Information (L)(M)(H)11
πŸ’Ό NIST CSF v2.0 β†’ πŸ’Ό PR.DS-10: The confidentiality, integrity, and availability of data-in-use are protected67

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό AU-9(1) Protection of Audit Information _ Hardware Write-once Media
πŸ’Ό AU-9(2) Protection of Audit Information _ Store on Separate Physical Systems or Components
πŸ’Ό AU-9(3) Protection of Audit Information _ Cryptographic Protection
πŸ’Ό AU-9(4) Protection of Audit Information _ Access by Subset of Privileged Users22
πŸ’Ό AU-9(5) Protection of Audit Information _ Dual Authorization
πŸ’Ό AU-9(6) Protection of Audit Information _ Read-only Access
πŸ’Ό AU-9(7) Protection of Audit Information _ Store on Component with Different Operating System

Policies (2)​

PolicyLogic CountFlags
πŸ“ AWS CloudTrail is not encrypted with KMS CMK 🟒1🟒 x6
πŸ“ AWS CloudTrail Log File Validation is not enabled 🟒1🟒 x6