NIST SP 800-66 Rev 2
Technical

NIST SP 800-66 Rev 2 164.312(b): Audit Controls (Standard)

Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. NIST recommends central log management aligned to SP 800-92.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 115 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 23 controls

  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 10.2.1.1 10.2.1.1 Logs capture individual user access to cardholder data
  • 10.2.1.3 10.2.1.3 Access to the audit logs is itself logged
  • 10.2.1.5 10.2.1.5 Logs capture changes to identification and authentication credentials
  • 10.2.1.6 10.2.1.6 Logs capture initialization and stopping of audit logs
  • 10.2.1.7 10.2.1.7 Logs capture creation and deletion of system-level objects
  • 10.2.2 10.2.2 Required details recorded for each auditable event
  • 10.6.2 10.6.2 Systems configured to correct and consistent time
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 10.7.3 10.7.3 Respond promptly to critical security control failures
  • 11.2.1 11.2.1 Detect authorized and rogue wireless access points
  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 11.5.2 11.5.2 Change detection on critical files
  • 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program
  • 12.6.1 12.6.1 Formal security awareness program
  • 5.3.4 5.3.4 Anti-malware audit logs enabled and retained
  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 6.4.2 6.4.2 Automated web attack detection and prevention
  • 9.2.3 9.2.3 Physical protection of network hardware and lines

NIST SP 800-53 Rev 5 · 13 controls

CIS Controls v8 · 12 controls

  • CIS-1.3 Utilize an Active Discovery Tool
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.3 Address Unauthorized Software
  • CIS-3.14 Log Sensitive Data Access
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.5 Perform Automated Vulnerability Scans of Internal Enterprise Assets
  • CIS-7.6 Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.2 Collect Audit Logs
  • CIS-8.5 Collect Detailed Audit Logs
  • CIS-8.6 Collect DNS Query Audit Logs
  • CIS-8.9 Centralize Audit Logs

SOC 2 · 7 controls

  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • ASBv3-DS-7 Enable logging and monitoring in DevOps
  • ASBv3-LT-6 Configure log storage retention
  • LT-3 Enable logging for security investigation
  • LT-4 Enable network logging for security investigation
  • LT-5 Centralize security log management and analysis

C5 (Germany) · 5 controls

  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-OPS-12 Logging and Monitoring - Access, Storage and Deletion
  • C5-OPS-13 Logging and Monitoring - Identification of Events
  • C5-OPS-14 Logging and Monitoring - Storage of the Logging Data
  • C5-PSS-04 Error handling and Logging Mechanisms

FedRAMP High · 5 controls

  • AU-1 Policy and Procedures
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-6 Audit Record Review, Analysis, and Reporting

FedRAMP Moderate · 5 controls

  • AU-1 Policy and Procedures
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-3 Content of Audit Records
  • AU-6 Audit Record Review, Analysis, and Reporting

CMMC 2.0 · 4 controls

ISO 27001:2022 · 4 controls

  • 5.7 Threat intelligence
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.19 Installation of software on operational systems
  • NIST-CSF-DE.AE-03 Information is correlated from multiple sources
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented

NIST SP 800-161 Rev 1 · 4 controls

NIST SP 800-171 Rev 3 · 4 controls

ACSC Essential Eight · 3 controls

  • E8-ADMIN-ML2 Restrict Administrative Privileges (ML2)
  • E8-APP-ML2 Application Control (ML2)
  • E8-UAH-ML3 User Application Hardening - Maturity Level 3
  • SEC04-BP01 Configure service and application logging
  • SEC04-BP02 Capture logs, findings, and metrics in standardized locations

ISO 27002:2022 · 2 controls

  • 8.15 Logging
  • 8.8 Management of technical vulnerabilities

ISO 27701:2019 · 2 controls

  • 6.10.1 Network security management
  • 6.9.4 Logging and monitoring
  • ANSSI-HYG-36 Enable and Configure Logging on the Most Important Components
  • ASD37-33 Capture network traffic (Limited)
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment

NIST SP 800-172 · 1 control

  • 3.14.2e Monitor Organizational Systems with Specialized Capabilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technical

Query this from an agent

The graph holds this control, the 115 it maps to, and the evidence behind each claim, over MCP and REST.