{"data":{"id":"AU-09","name":"Protection of Audit Information","family":"AU","family_name":"Audit and Accountability","withdrawn":false,"description":"a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and\nb. Alert [Assignment: organization-defined personnel or roles] upon detection of unauthorized access, modification, or deletion of audit information.","supplemental_guidance":"Audit information includes all information needed to successfully audit system activity, such as audit records, audit log settings, audit reports, and personally identifiable information. Audit logging tools are those programs and devices used to conduct system audit and logging activities. Protection of audit information focuses on technical protection and limits the ability to access and execute audit logging tools to authorized individuals. Physical protection of audit information is addressed by both media protection controls and physical and environmental protection controls.","enhancements":[{"id":"AU-09(01)","name":"Hardware Write-once Media","statement":"Write audit trails to hardware-enforced, write-once media.","baselines":[]},{"id":"AU-09(02)","name":"Store on Separate Physical Systems or Components","statement":"Store audit records [Assignment: organization-defined frequency] in a repository that is part of a physically different system or system component than the system or component being audited.","baselines":["high"]},{"id":"AU-09(03)","name":"Cryptographic Protection","statement":"Implement cryptographic mechanisms to protect the integrity of audit information and audit tools.","baselines":["high"]},{"id":"AU-09(04)","name":"Access by Subset of Privileged Users","statement":"Authorize access to management of audit logging functionality to only [Assignment: organization-defined subset of privileged users or roles].","baselines":["moderate","high"]},{"id":"AU-09(05)","name":"Dual Authorization","statement":"Enforce dual authorization for [Selection (one or more): movement; deletion] of [Assignment: organization-defined audit information].","baselines":[]},{"id":"AU-09(06)","name":"Read-only Access","statement":"Authorize read-only access to audit information to [Assignment: organization-defined subset of privileged users or roles].","baselines":[]},{"id":"AU-09(07)","name":"Store on Component with Different Operating System","statement":"Store audit information on a component running a different operating system than the system or component being audited.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"AU-09","name":"Protection of Audit Information","description":"a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and\nb. Alert [Assignment: organization-defined personnel or roles] upon detection of unauthorized access, modification, or deletion of audit information.","discussion":"Audit information includes all information needed to successfully audit system activity, such as audit records, audit log settings, audit reports, and personally identifiable information. Audit logging tools are those programs and devices used to conduct system audit and logging activities. Protection of audit information focuses on technical protection and limits the ability to access and execute audit logging tools to authorized individuals. Physical protection of audit information is addressed by both media protection controls and physical and environmental protection controls.","related_controls":["AC-03","AC-06","AU-06","AU-11","AU-14","AU-15","MP-02","MP-04","PE-02","PE-03","PE-06","SA-08","SC-08","SI-04"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Adds new alert for specified individuals or roles upon detection of unauthorized access, modification, or deletion of audit information New parameter supports specifying the individuals or roles to receive alerts Discussion reference to PII"}},"compliance_mappings":{"iso_27001_2022":["7.5","A.5.33","A.8.15"],"iso_27002_2022":["5.28","5.33","8.15"],"cobit_2019":[],"pci_dss_v4":["10.3"],"nist_csf_2":["PR.DS-10","RS.AN-06","RS.AN-07"],"cis_controls_v8":["CIS 8"],"soc2_tsc":["PI1.4","PI1.5"],"finos_ccc":[],"iso_42001_2023":["A.6.2.8"],"iec_62443":["3-3 SR 6.1"],"asd_e8":[],"nis2":[],"apra_cps_234":["Para 22-23"],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["OPS.1.1.5"],"anssi":["Hygiene.29","SecNumCloud.13.7"],"osfi_b13":["B-13.3.2","B-13.3.3"],"finma_circular":["IV.B.d(59)","IV.C(66)","IV.C(67)"],"gdpr":["Art.5(1)(f)","Art.32(1)(b)"],"dora":["Art.10(1)"],"bio2":["5.28","5.33","8.15"],"rbi_csf":["Annex1.16","ITGRCA.15"],"fisc":["FISC.O11"],"lgpd_bcb":["BCB.Art.3","BCB.Art.9","BCB.Art.15","BCB.Art.20","LGPD.Art.46"],"hkma_tme1":[],"mlps_2":["8.1.3.5","8.1.4.3","8.1.5.2"],"dnb_good_practice":["DNB.20.1"],"cra":["CRA.I.2f","CRA.I.2l"],"swift_cscf":["SWIFT.6.4"],"cbb_tm":["TM-12"],"cbuae":["CR-3"],"nca_ecc":["2-12"],"qatar_nia":["OS"],"uae_ia":["T7"],"bog_cisd":["CISD-VII"],"bom_ctrm":["4.2"],"cbe_csf":["CD-1"],"cbn_csf":["Part3.5"],"popia":["s19"],"sa_js2":["JS2-7.3"],"bot_cyber":["Ch3.1"],"cpmi_pfmi":["CG.DE"],"eba_ict":["3.4.5","3.5(c)"],"ecb_croe":["CROE.2.4"],"ffiec_is":["III.B"],"hipaa_sr":["§164.308(a)(1)(ii)(D)","§164.312(b)"],"iosco_cyber":["DET-1"],"nydfs_500":["500.6"],"sebi_cscrf":["DE.AU","RS.AN"],"cmmc_2":["AU"],"nerc_cip":[],"nrc_73_54":["RG5.71-A-AU"],"tsa_psd":[],"ieee_1686":["5.2"],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":["Sec 5.5"],"pci_pts":["L"],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":["CC Part 2 — FAU"],"isae_3402":[],"fca_sysc_13":["SYSC 13.G.4"],"fda_21_cfr_11":["§11.10(b)","§11.10(e)"],"fda_cyber":["SA-5"],"hitrust_csf":["09.g","11.c"],"iso_27799":["12.4"],"lloyds_ms":["MS8.12"],"naic_ds":["4-audit","7"],"nhs_dspt":[],"pra_ss1_23":["P-IT.2"],"solvency_ii":["Pillar3-Reporting"],"owasp_masvs_v2":[],"csa_ccm_v4":["IAM-12","LOG-02","LOG-04","LOG-09"],"csa_aicm":["IAM-12","LOG-02","LOG-04","LOG-09"],"ccss_v9":["1.04.5","1.05.2","2.04.1","2.04.2","2.04.3"],"mica":["Art.63(2)","Art.82(1)"],"basel_sco60":["SCO60.23","SCO60.62","SCO60.66"],"bssc":["GSP-12","KMS-09","TIS-07"],"sec_custody_digital":["SEC-CD-05","SEC-CD-15","SEC-CD-16"],"dpdpa":[]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.5.33 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 PR.DS-10 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-016","SP-021","SP-022","SP-025","SP-026","SP-029","SP-031","SP-033","SP-036","SP-053","SP-054"]}}