NIST SP 800-53 Revision 5.1 HIGH
AU Audit and Accountability

NIST SP 800-53 Revision 5.1 HIGH AU-7(1): Automatic Processing

Process audit records for events of interest based on defined criteria.

What else in your programme already covers this

This control maps to 19 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 4 controls

PCI DSS 4.0 · 4 controls

  • 10.2.1 Audit logs enabled on system components
  • 10.3.3 Logs backed up to central server
  • 10.4.1 Daily log review for critical systems
  • 10.4.1.1 Automated mechanisms for log review

NIST SP 800-53 Rev 5 · 2 controls

  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations

CMMC 2.0 · 1 control

ISO 27001:2022 · 1 control

  • 8.16 Monitoring activities

ISO 27002:2022 · 1 control

  • 8.16 Monitoring activities
  • NIST-CSF-DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
  • 03.03.06 Audit Record Reduction and Report Generation

NIST SP 800-172 · 1 control

  • 3.11.3e Advanced Automation and Analytics Capabilities

SOC 2 · 1 control

  • SOC2-CC7.1 Detection and monitoring procedures for security events are in place

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in AU Audit and Accountability

Query this from an agent

The graph holds this control, the 19 it maps to, and the evidence behind each claim, over MCP and REST.