NIST SP 800-53 Rev 5 MODERATE
AU Audit and Accountability

NIST SP 800-53 Rev 5 MODERATE AU-2: Event Logging

Identify event types selected for logging including FedRAMP minimum list; review and update at least annually.

What else in your programme already covers this

This control maps to 45 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 8 controls

  • 10.2.1 Audit logs enabled on system components
  • 10.2.1.1 Log all user access to CHD
  • 10.2.1.3 Log access to audit logs
  • 10.2.1.4 Log invalid logical access attempts
  • 10.2.1.7 Log creation and deletion of system level objects
  • 11.5.2 Change detection mechanism (FIM)
  • 12.4.1 Executive management responsibility for the PCI DSS compliance program (service providers)
  • 5.3.4 Audit logs for anti-malware enabled

CIS Controls v8 · 5 controls

  • ASBv3-DS-7 Enable logging and monitoring in DevOps
  • LT-3 Enable logging for security investigation
  • LT-4 Enable network logging for security investigation

C5 (Germany) · 3 controls

SOC 2 · 3 controls

  • SOC2-CC5.2 COSO principle 11: Selects and develops general controls over technology
  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • SOC2-CC7.2 Monitors system components for anomalies indicating malicious acts

ACSC Essential Eight · 2 controls

  • E8-MFA-ML3 Multi-Factor Authentication - Maturity Level 3
  • E8-UAH-ML3 User Application Hardening - Maturity Level 3

CMMC 2.0 · 2 controls

ISO 27001:2022 · 2 controls

  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components
  • SEC04-BP01 Configure service and application logging
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

HIPAA Security Rule · 1 control

ISO 27002:2022 · 1 control

ISO 27018:2019 · 1 control

ISO/IEC 42001:2023 · 1 control

  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AU Audit and Accountability

Query this from an agent

The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.