|
controlAU-14
Session Audit (AU-14)
Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.
auditaccountabilitylogging
Why These Connect
Maps To1
These are equivalent or closely aligned requirements in other frameworks.
Supports19
These related controls work together — a change to one may affect the others.
Enhances3
These enhancements add specific capabilities or refinements to the base control.
Related Controls(11)
AU-3Content of Audit Records (AU-3)
LMH
AU-4Audit Log Storage Capacity (AU-4)LMH
AU-5Response to Audit Logging Process Failures (AU-5)LMH
AU-8Time Stamps (AU-8)LMH
AU-9Protection of Audit Information (AU-9)LMH
AU-11Audit Record Retention (AU-11)LMH
AU-12Audit Record Generation (AU-12)LMH
AC-3Access Enforcement (AC-3)LMH
AC-8System Use Notification (AC-8)LMH
AU-2Event Logging (AU-2)LMH
SI-4System Monitoring (SI-4)LMH
Cross-Framework Mappings(1)
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
Organization-Defined Parameters(3)
Assignmentorganization-defined users or roles
SelectionSelection (one-or-more): record / view / hear / log
Assignmentorganization-defined circumstances