NIST SP 800-53 Revision 5.1 HIGH
AU Audit and Accountability

NIST SP 800-53 Revision 5.1 HIGH AU-7: Audit Record Reduction and Report Generation

Provide capability for audit record reduction and on-demand report generation.

What else in your programme already covers this

This control maps to 18 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.11 Conduct Audit Log Reviews
  • CIS-8.2 Collect Audit Logs
  • CIS-8.9 Centralize Audit Logs
  • ASBv3-IR-4 Detection and analysis - investigate an incident
  • LT-5 Centralize security log management and analysis

ISO 27001:2022 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations

CMMC 2.0 · 1 control

ISO 27002:2022 · 1 control

  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • 03.03.06 Audit Record Reduction and Report Generation

PCI DSS 4.0 · 1 control

  • 10.4.1.1 Automated mechanisms for log review

SOC 2 · 1 control

  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AU Audit and Accountability

Query this from an agent

The graph holds this control, the 18 it maps to, and the evidence behind each claim, over MCP and REST.