|
controlAU-3
Content of Audit Records (AU-3)
Ensure that audit records contain information that establishes the following:
Security Baselines
LOWMODERATEHIGH
auditaccountabilitylogging
Why These Connect
Maps To4
These are equivalent or closely aligned requirements in other frameworks.
Baselined In3
This control is included in the linked security baseline (LOW, MODERATE, or HIGH).
Supports14
These related controls work together — a change to one may affect the others.
Mitigates2
This control helps defend against or reduce the risk of the linked threat technique.
Enhances3
These enhancements add specific capabilities or refinements to the base control.
Related Controls(11)
AU-2Event Logging (AU-2)
LMH
AU-8Time Stamps (AU-8)LMH
AU-12Audit Record Generation (AU-12)LMH
AU-14Session Audit (AU-14)MA-4Nonlocal Maintenance (MA-4)LMH
PL-9Central Management (PL-9)SA-8Security and Privacy Engineering Principles (SA-8)LMH
SI-7Software, Firmware, and Information Integrity (SI-7)MH
SI-11Error Handling (SI-11)MH
AU-7Audit Record Reduction and Report Generation (AU-7)MH
AU-16Cross-organizational Audit Logging (AU-16)Threat Coverage(2 ATT&CK techniques)
Cross-Framework Mappings(4)
PR.PS-04PR.PS-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20222 mappingsFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
HIPAAHIPAA Security Rule1 mappingFinal
NIST OLIR informative reference — HIPAA Security Rule to SP 800-53 Rev 5
PR.PS-04PR.PS-04Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5