Frameworks / NIST SP 800-53 Revision 5.1 HIGH / AU-5 NIST SP 800-53 Revision 5.1 HIGH
AU Audit and Accountability
NIST SP 800-53 Revision 5.1 HIGH AU-5: Response to Audit Logging Process Failures Alert defined personnel on audit failure within FedRAMP timeframe; take defined action (overwrite oldest, shutdown, stop processing).
What else in your programme already covers this This control maps to 25 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-13.1 Centralize Security Event Alerting CIS-17.4 Establish and Maintain an Incident Response Process CIS-8.1 Establish and Maintain an Audit Log Management Process CIS-8.2 Collect Audit Logs 5.24 Information security incident management planning and preparation 5.25 Assessment and decision on information security events 5.26 Response to information security incidents 8.15 Logging NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared 10.2.1.6 Log initialization, stopping, or pausing of logs 10.7.1 Critical security control failure detection (SP) 10.7.2 Critical security control failure detection (all entities) 10.7.3 Failure response timeline 5.24 Information security incident management planning and preparation 5.26 Response to information security incidents 8.15 Logging C5-OPS-17 Logging and Monitoring - Availability of the Monitoring Software 03.03.04 Response to Audit Logging Process Failures SOC2-CC7.4 Responds to identified security incidents through defined procedures Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in AU Audit and Accountability Query this from an agent The graph holds this control, the 25 it maps to, and the evidence behind each claim, over MCP and REST.