|
controlAU-2

Event Logging (AU-2)

Identify the types of events that the system is capable of logging in support of the audit function: [organization-defined]; Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged; Specify the following event types for logging within the system: [organization-defined]; Provide a rationale for why the event types selected for logging are deemed to be adequate to support after-t

Security Baselines

LOWMODERATEHIGH
auditaccountabilitylogging

Why These Connect

Maps To4

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports43

These related controls work together — a change to one may affect the others.

Mitigates4

This control helps defend against or reduce the risk of the linked threat technique.

Enhances4

These enhancements add specific capabilities or refinements to the base control.

Related Controls(37)

Cross-Framework Mappings(4)

PR.PS-04PR.PS-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
PR.PS-04PR.PS-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(4)

Assignmentorganization-defined event types
Assignmentorganization-defined event types (subset of AU-02_ODP[01])
Assignmentorganization-defined frequency or situation
Assignmentorganization-defined frequency

Control Enhancements(4)