Frameworks / NIST SP 800-53 Revision 5.1 HIGH / AU-4 NIST SP 800-53 Revision 5.1 HIGH
AU Audit and Accountability
NIST SP 800-53 Revision 5.1 HIGH AU-4: Audit Log Storage Capacity Allocate audit log storage capacity to accommodate FedRAMP-defined retention period.
What else in your programme already covers this This control maps to 19 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
10.3.3 Logs backed up to central server 10.5.1 Audit log retention 12 months 12.1.3 Information security roles and responsibilities defined and acknowledged 8.15 Logging 8.6 Capacity management SOC2-A1.1 Maintains capacity to meet availability commitments SOC2-CC7.1 Detection and monitoring procedures for security events are in place SEC04-BP02 Capture logs, findings, and metrics in standardized locations C5-OPS-14 Logging and Monitoring - Storage of the Logging Data CFTC-SS-12 Capacity and Performance Planning Category Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in AU Audit and Accountability Query this from an agent The graph holds this control, the 19 it maps to, and the evidence behind each claim, over MCP and REST.