|
controlAU-14

Session Audit (AU-14)

Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and in accordance with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

auditaccountabilitylogging

Why These Connect

Maps To1

These are equivalent or closely aligned requirements in other frameworks.

Supports19

These related controls work together — a change to one may affect the others.

Enhances3

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(1)

ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022

Organization-Defined Parameters(3)

Assignmentorganization-defined users or roles
SelectionSelection (one-or-more): record / view / hear / log
Assignmentorganization-defined circumstances

Control Enhancements(3)