NIST SP 800-53 Revision 5.1 HIGH
AU Audit and Accountability

NIST SP 800-53 Revision 5.1 HIGH AU-4: Audit Log Storage Capacity

Allocate audit log storage capacity to accommodate FedRAMP-defined retention period.

What else in your programme already covers this

This control maps to 19 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 3 controls

PCI DSS 4.0 · 3 controls

  • 10.3.3 Logs backed up to central server
  • 10.5.1 Audit log retention 12 months
  • 12.1.3 Information security roles and responsibilities defined and acknowledged

ISO 27001:2022 · 2 controls

  • 8.15 Logging
  • 8.6 Capacity management

SOC 2 · 2 controls

  • SOC2-A1.1 Maintains capacity to meet availability commitments
  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place
  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations

C5 (Germany) · 1 control

  • C5-OPS-14 Logging and Monitoring - Storage of the Logging Data
  • CFTC-SS-12 Capacity and Performance Planning Category

DORA · 1 control

ISO 27002:2022 · 1 control

  • 8.6 Capacity management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AU Audit and Accountability

Query this from an agent

The graph holds this control, the 19 it maps to, and the evidence behind each claim, over MCP and REST.