Frameworks / NIST SP 800-53 Rev 5 LOW / AU-9 NIST SP 800-53 Rev 5 LOW
AU Audit and Accountability
NIST SP 800-53 Rev 5 LOW AU-9: Protection of Audit Information Protect audit information and tools from unauthorized access, modification, deletion.
What else in your programme already covers this This control maps to 43 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved 10.3.1 Read access to logs restricted 10.3.2 Logs protected from modification 10.3.4 File integrity or change detection on logs 10.6.3 Time settings protected SOC2-C1.1 Confidential information is identified and protected during receipt, processing, storage SOC2-CC6.1 Implements logical access security software, infrastructure and architectures over protected information assets SOC2-CC6.3 Role-based access and least privilege are enforced SOC2-CC7.1 Detection and monitoring procedures for security events are in place ASBv3-DP-8 Ensure security of key and certificate repository ASBv3-LT-6 Configure log storage retention ASBv3-PA-7 Follow just enough administration (least privilege) principle C5-OPS-12 Logging and Monitoring - Access, Storage and Deletion C5-OPS-14 Logging and Monitoring - Storage of the Logging Data C5-OPS-16 Logging and Monitoring - Configuration 5.28 Collection of evidence 5.33 Protection of records 8.18 Use of privileged utility programs NIST800-AU-10 Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined] NIST800-AU-9 Protection of audit information SP800-53-AU Audit and Accountability Family 5.28 Collection of evidence 5.33 Protection of records MYHR-SEC-2 Access controls and user account management 6.9.4 Logging and monitoring 03.03.08 Protection of Audit Information Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in AU Audit and Accountability Query this from an agent The graph holds this control, the 43 it maps to, and the evidence behind each claim, over MCP and REST.