NIST SP 800-53 Rev 5
AU - Audit and Accountability

NIST SP 800-53 Rev 5 NIST800-AU-3: AU-3 Content of Audit Records

Ensure that audit records contain information that establishes the following: a. What type of event occurred; b. When the event occurred; c. Where the event occurred; d. Source of the event; e. Outcome of the event; and f. Identity of any individuals, subjects, or objects/entities associated with the event.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 87 controls across 51 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 4 controls

  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data
  • 10.2.1.2 10.2.1.2 Logs capture all administrative actions
  • 10.2.2 10.2.2 Required details recorded for each auditable event

BSI IT-Grundschutz · 3 controls

  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

CIS Controls v8 · 3 controls

SOC 2 · 3 controls

  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • SOC2-P6.3 P6.3 Record of unauthorised disclosures and breaches

C5 (Germany) · 2 controls

  • C5-OPS-11 Logging and Monitoring - Metadata Management Concept
  • C5-OPS-15 Logging and Monitoring - Accountability

CMMC 2.0 · 2 controls

FedRAMP High · 2 controls

  • AU-3 Content of Audit Records
  • AU-3(1) Additional Audit Information

FedRAMP Moderate · 2 controls

  • AU-3 Content of Audit Records
  • AU-3(1) Additional Audit Information
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components
  • SEC04-BP01 Configure service and application logging
  • LT-3 Enable logging for security investigation

EU AI Act · 1 control

  • CAT-D3-2 Detective controls
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

HIPAA Security Rule · 1 control

  • 62351-14 Cyber security event logging

ISO 27001:2022 · 1 control

ISO 27002:2022 · 1 control

ISO 27799:2025 · 1 control

  • ISO27799-05 Audit trail for ePHI access
  • ISO-25012-4.11 Traceability

ISO/IEC 27011:2024 · 1 control

  • 27011-8.4 Logging and monitoring

ISO/IEC 27043:2015 · 1 control

  • ISO27043-24 Logging and monitoring

ISO/SAE 21434 · 1 control

  • ISO21434-24 Logging and monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-190 · 1 control

  • AU-3 AU-3 Content of Audit Records
  • AU-3 AU-3 Content of Audit Records
  • AU-3 AU-3 Content of Audit Records
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • ORANWG11-7 Logging, Monitoring, Incident Response, and Denial-of-Service Resilience

OWASP SAMM · 1 control

  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

OpenSSF Scorecard · 1 control

  • OSSFSC-7 Webhook Authentication, Contributors Diversity, Aggregate Score
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • PICSGMP-4 Chapter 4: Documentation - System, Record-Keeping, Data Integrity

PTES · 1 control

  • PTESPHASE-3 Threat Modeling
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • CISABD-1 Take Ownership of Customer Security Outcomes

South Korea ISMS-P · 1 control

  • ISMSP-SYS-03 Security Monitoring and Log Management
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AU - Audit and Accountability

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-AU-3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 87 it maps to, and the evidence behind each claim, over MCP and REST.