NIST SP 800-53 Rev 5 LOW
AU Audit and Accountability

NIST SP 800-53 Rev 5 LOW AU-3: Content of Audit Records

Audit records must contain: type, when, where, source, outcome, identity associated.

What else in your programme already covers this

This control maps to 30 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

SOC 2 · 3 controls

  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • SOC2-CC7.2 Monitors system components for anomalies indicating malicious acts
  • SOC2-P6.3 Creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy. The following point of focus, which

C5 (Germany) · 2 controls

  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept
  • C5-OPS-15 Logging and Monitoring - Accountability

CMMC 2.0 · 2 controls

ISO 27701:2019 · 2 controls

  • 6.9.4 Logging and monitoring
  • 8.5.3 Records of PII disclosure to third parties
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

NIST SP 800-53 Rev 5 · 2 controls

PCI DSS 4.0 · 2 controls

  • 10.2.2 Audit log content
  • 5.3.4 Audit logs for anti-malware enabled
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components
  • SEC04-BP01 Configure service and application logging
  • LT-3 Enable logging for security investigation

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

ISO 27002:2022 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AU Audit and Accountability

Query this from an agent

The graph holds this control, the 30 it maps to, and the evidence behind each claim, over MCP and REST.