|
controlAU-12
Audit Record Generation (AU-12)
Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on [organization-defined]; Allow [organization-defined] to select the event types that are to be logged by specific components of the system; and Generate audit records for the event types defined in [AU-2c](#au-2_smt.c) that include the audit record content defined in [AU-3](#au-3).
Security Baselines
LOWMODERATEHIGH
auditaccountabilitylogging
Why These Connect
Maps To9
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports30
These related controls work together — a change to one may affect the others.
Enhances4
These enhancements add specific capabilities or refinements to the base control.
Related Controls(22)
AC-2Account Management (AC-2)
LMH
AU-2Event Logging (AU-2)LMH
AU-3Content of Audit Records (AU-3)LMH
AU-4Audit Log Storage Capacity (AU-4)LMH
AU-5Response to Audit Logging Process Failures (AU-5)LMH
AU-7Audit Record Reduction and Report Generation (AU-7)MH
AU-8Time Stamps (AU-8)LMH
AC-6Least Privilege (AC-6)MH
AC-17Remote Access (AC-17)LMH
AU-6Audit Record Review, Analysis, and Reporting (AU-6)LMH
AU-14Session Audit (AU-14)CM-5Access Restrictions for Change (CM-5)LMH
MA-4Nonlocal Maintenance (MA-4)LMH
MP-4Media Storage (MP-4)MH
PM-12Insider Threat Program (PM-12)SA-8Security and Privacy Engineering Principles (SA-8)LMH
SC-18Mobile Code (SC-18)MH
SI-3Malicious Code Protection (SI-3)LMH
SI-4System Monitoring (SI-4)LMH
SI-7Software, Firmware, and Information Integrity (SI-7)MH
SI-10Information Input Validation (SI-10)MH
PE-6Monitoring Physical Access (PE-6)LMH
Cross-Framework Mappings(9)
PR.PS-04PR.PS-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-01DE.CM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-03DE.CM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-09DE.CM-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.PS-04PR.PS-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-01DE.CM-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-03DE.CM-03Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
DE.CM-09DE.CM-09Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
Organization-Defined Parameters(2)
Assignmentorganization-defined system components
Assignmentorganization-defined personnel or roles