Implement NIST 800-53 AU Audit and Accountability family + CM Configuration Management family + Information System Continuous Monitoring (ISCM) program per MARS-E v2.0. Audit events include logon + logoff + privileged operations + access to PII or PHI or FTI + administrative actions + configuration changes + security tool events + suspected unauthorised activity. Audit log retention minimum 90 days online + 7 years offline (1 year HIPAA + 6 years HIPAA-extended + IRS Pub 1075 minimum 6 years + state retention). Centralised SIEM (Security Information and Event Management) with SOC monitoring. Audit log integrity protection via cryptographic hashing + WORM (Write Once Read Many) storage + access restrictions. Configuration management with approved baseline + change control board + drift detection. Continuous monitoring under NIST 800-137 ISCM with monthly reporting to CMS. Vulnerability scanning weekly internal + monthly external + penetration testing annually. Annual independent assessment by 3PAO (Third Party Assessment Organisation) per FedRAMP-aligned process. IRS Pub 1075 Section 5 Audit Trail requirements (separate FTI audit + reconciliation + 6-year retention + IRS Safeguard Activity Report SAFER).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.