NIST SP 800-53 Rev 5 LOW AU-3: Content of Audit Records
Audit records must contain: type, when, where, source, outcome, identity associated.
What else in your programme already covers this
This control maps to 30 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
SOC2-CC7.1 Detection and monitoring procedures for security events are in place
SOC2-CC7.2 Monitors system components for anomalies indicating malicious acts
SOC2-P6.3 Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy. The following point of focus, which