Audit and Accountability (AU)

Ensure that audit records contain information that establishes the following: a. What type of event occurred; b. When the event occurred; c. Where the event occurred; d. Source of the event; e. Outcome of the event; and f. Identity of any individuals, subjects, or objects/entities associated with the event.


Login

Audit and Accountability (AU)

Generate audit records containing the following additional information: [Assignment: organization-defined additional information].


Login

Audit and Accountability (AU)

[Withdrawn: Incorporated into AU-12.]


Login

Audit and Accountability (AU)

Limit personally identifiable information contained in audit records to the following elements identified in the privacy risk assessment: [Assignment: organization-defined elements].


Login

Audit and Accountability (AU)

Allocate audit log storage capacity to accommodate [Assignment: organization-defined audit log retention requirements].


Login

Audit and Accountability (AU)

Transfer audit logs [Assignment: organization-defined frequency] to a different system, system component, or media other than the system or system component conducting the logging.


Login

Audit and Accountability (AU)

a. Alert [Assignment: organization-defined personnel or roles] within [Assignment: organization-defined time period] in the event of an audit logging process failure; and b. Take the following additional actions: [Assignment: organization-defined additional actions].


Login

Audit and Accountability (AU)

Provide a warning to [Assignment: organization-defined personnel, roles, and/or locations] within [Assignment: organization-defined time period] when allocated audit log storage volume reaches [Assignment: organization-defined percentage] of repository maximum audit log storage capacity.


Login

Audit and Accountability (AU)

Provide an alert within [Assignment: organization-defined real-time period] to [Assignment: organization-defined personnel, roles, and/or locations] when the following audit failure events occur: [Assignment: organization-defined audit logging failure events requiring real-time alerts].


Login

Audit and Accountability (AU)

Enforce configurable network communications traffic volume thresholds reflecting limits on audit log storage capacity and [Selection: reject; delay] network traffic above those thresholds.


Login