|
controlAU-11

Audit Record Retention (AU-11)

Retain audit records for [organization-defined] to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements.

Security Baselines

LOWMODERATEHIGH
auditaccountabilitylogging

Why These Connect

Maps To3

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports13

These related controls work together — a change to one may affect the others.

Enhances1

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(3)

PR.PS-04PR.PS-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.PS-04PR.PS-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Control Enhancements(1)