Frameworks / NIST SP 800-66 Rev 2 / 164.312(b) NIST SP 800-66 Rev 2
Technical
NIST SP 800-66 Rev 2 164.312(b): Audit Controls (Standard) Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. NIST recommends central log management aligned to SP 800-92.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 115 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.2.5 1.2.5 Allowed services, protocols and ports justified 10.2.1 10.2.1 Audit logging enabled on all system components 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data 10.2.1.3 10.2.1.3 Access to the audit logs is itself logged 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials 10.2.1.6 10.2.1.6 Logs capture initialization and stopping of audit logs 10.2.1.7 10.2.1.7 Logs capture creation and deletion of system-level objects 10.2.2 10.2.2 Required details recorded for each auditable event 10.6.2 10.6.2 Systems configured to correct and consistent time 10.6.3 10.6.3 Time sync configuration and time data protected 10.7.2 10.7.2 Detect and alert on critical security control failures 10.7.3 10.7.3 Respond promptly to critical security control failures 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.3.1 11.3.1 Quarterly internal vulnerability scans 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 11.5.2 11.5.2 Change detection on critical files 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program 12.6.1 12.6.1 Formal security awareness program 5.3.4 5.3.4 Anti-malware audit logs enabled and retained 6.2.1 6.2.1 Secure development of bespoke and custom software 6.4.1 6.4.1 Public web application review or automated protection 6.4.2 6.4.2 Automated web attack detection and prevention 9.2.3 9.2.3 Physical protection of network hardware and lines CIS-1.3 Utilize an Active Discovery Tool CIS-2.2 Ensure Authorized Software is Currently Supported CIS-2.3 Address Unauthorized Software CIS-3.14 Log Sensitive Data Access CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets CIS-8.1 Establish and Maintain an Audit Log Management Process CIS-8.2 Collect Audit Logs CIS-8.5 Collect Detailed Audit Logs CIS-8.6 Collect DNS Query Audit Logs CIS-8.9 Centralize Audit Logs SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13) SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.2 CC7.2 Monitoring system components for anomalies ASBv3-DS-7 Enable logging and monitoring in DevOps ASBv3-LT-6 Configure log storage retention LT-3 Enable logging for security investigation LT-4 Enable network logging for security investigation LT-5 Centralize security log management and analysis C5-OPS-10 Logging and Monitoring - Concept C5-OPS-12 Logging and Monitoring - Access, Storage and Deletion C5-OPS-13 Logging and Monitoring - Identification of Events C5-OPS-14 Logging and Monitoring - Storage of the Logging Data C5-PSS-04 Error handling and Logging Mechanisms AU-1 Policy and Procedures AU-12 Audit Record Generation AU-2 Event Logging AU-3 Content of Audit Records AU-6 Audit Record Review, Analysis, and Reporting AU-1 Policy and Procedures AU-12 Audit Record Generation AU-2 Event Logging AU-3 Content of Audit Records AU-6 Audit Record Review, Analysis, and Reporting 5.7 Threat intelligence 8.15 Logging 8.16 Monitoring activities 8.19 Installation of software on operational systems NIST-CSF-DE.AE-03 Information is correlated from multiple sources NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented E8-ADMIN-ML2 Restrict Administrative Privileges (ML2) E8-APP-ML2 Application Control (ML2) E8-UAH-ML3 User Application Hardening - Maturity Level 3 SEC04-BP01 Configure service and application logging SEC04-BP02 Capture logs, findings, and metrics in standardized locations 8.15 Logging 8.8 Management of technical vulnerabilities 6.10.1 Network security management 6.9.4 Logging and monitoring ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components ASD37-33 Capture network traffic (Limited) AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment 3.14.2e Monitor Organizational Systems with Specialized Capabilities Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Technical Query this from an agent The graph holds this control, the 115 it maps to, and the evidence behind each claim, over MCP and REST.