{"data":{"id":"AU-12","name":"Audit Record Generation","family":"AU","family_name":"Audit and Accountability","withdrawn":false,"description":"a. Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2a on [Assignment: organization-defined system components];\nb. Allow [Assignment: organization-defined personnel or roles] to select the event types that are to be logged by specific components of the system; and\nc. Generate audit records for the event types defined in AU-2c that include the audit record content defined in AU-3.","supplemental_guidance":"Audit records can be generated from many different system components. The event types specified in AU-2d are the event types for which audit logs are to be generated and are a subset of all event types for which the system can generate audit records.","enhancements":[{"id":"AU-12(01)","name":"System-wide and Time-correlated Audit Trail","statement":"Compile audit records from [Assignment: organization-defined system components] into a system-wide (logical or physical) audit trail that is time-correlated to within [Assignment: organization-defined level of tolerance for the relationship between time stamps of individual records in the audit trail].","baselines":["high"]},{"id":"AU-12(02)","name":"Standardized Formats","statement":"Produce a system-wide (logical or physical) audit trail composed of audit records in a standardized format.","baselines":[]},{"id":"AU-12(03)","name":"Changes by Authorized Individuals","statement":"Provide and implement the capability for [Assignment: organization-defined individuals or roles] to change the logging to be performed on [Assignment: organization-defined system components] based on [Assignment: organization-defined selectable event criteria] within [Assignment: organization-defined time thresholds].","baselines":["high"]},{"id":"AU-12(04)","name":"Query Parameter Audits of Personally Identifiable Information","statement":"Provide and implement the capability for auditing the parameters of user query events for data sets containing personally identifiable information.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"AU-12","name":"Audit Record Generation","description":"a. Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2a on [Assignment: organization-defined system components];\nb. Allow [Assignment: organization-defined personnel or roles] to select the event types that are to be logged by specific components of the system; and\nc. Generate audit records for the event types defined in AU-2c that include the audit record content defined in AU-3.","discussion":"Audit records can be generated from many different system components. The event types specified in AU-2d are the event types for which audit logs are to be generated and are a subset of all event types for which the system can generate audit records.","related_controls":["AC-06","AC-17","AU-02","AU-03","AU-04","AU-05","AU-06","AU-07","AU-14","CM-05","MA-04","MP-04","PM-12","SA-08","SC-18","SI-03","SI-04","SI-07","SI-10"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"No significant changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":["7.5","A.8.15"],"iso_27002_2022":["8.15"],"cobit_2019":[],"pci_dss_v4":["10.2"],"nist_csf_2":["DE.CM-01","DE.CM-03","DE.CM-09","PR.PS-04"],"cis_controls_v8":["CIS 3.14","CIS 8","CIS 8.2"],"soc2_tsc":[],"finos_ccc":["CCC-C04","CCC-C17"],"iso_42001_2023":[],"iec_62443":["3-3 SR 2.8"],"asd_e8":[],"nis2":[],"apra_cps_234":["Para 22-23"],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["OPS.1.1.5"],"anssi":["Hygiene.29","SecNumCloud.13.7"],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":["Art.10(1)"],"bio2":["8.15"],"rbi_csf":["Annex1.16","Annex1.17","ITGRCA.15"],"fisc":["FISC.O2"],"lgpd_bcb":[],"hkma_tme1":["TME1.4.2","TME1.5.2","TME1.8.2"],"mlps_2":["8.1.3.5","8.1.4.3"],"dnb_good_practice":[],"cra":["CRA.I.2l"],"swift_cscf":["SWIFT.6.4"],"cbb_tm":["TM-12"],"cbuae":["CR-3"],"nca_ecc":["2-12"],"qatar_nia":["OS"],"uae_ia":["T7"],"bog_cisd":["CISD-VII"],"bom_ctrm":["4.2"],"cbe_csf":["CD-1"],"cbn_csf":["Part3.5"],"sa_js2":["JS2-7.3"],"bcbs_239":["Principle 4"],"bot_cyber":["Ch3.1"],"cpmi_pfmi":["CG.DE","PFMI.P17"],"eba_ict":["3.4.5","3.5(c)"],"ecb_croe":["CROE.2.4"],"ffiec_is":["II.C.15","II.C.18","III.B"],"hipaa_sr":["§164.308(a)(1)(ii)(D)","§164.308(a)(5)(ii)(C)","§164.312(b)"],"iosco_cyber":["DET-1","DET-4"],"nydfs_500":["500.6"],"sebi_cscrf":["DE.AU","DE.DP"],"cmmc_2":["AU"],"nerc_cip":[],"nrc_73_54":["RG5.71-A-AU"],"tsa_psd":[],"ieee_1686":["5.2"],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":["L"],"fips_140":[],"cbest":[],"tiber_eu":["TIBER.BT"],"pci_hsm":["6","8"],"common_criteria":["CC Part 2 — FAU"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.5"],"fda_21_cfr_11":["§11.10(e)","§11.50"],"fda_cyber":["SA-5"],"hitrust_csf":["09.g"],"iso_27799":["9.2","12.4"],"lloyds_ms":["MS2.1","MS8.12"],"naic_ds":["4-audit","4B"],"nhs_dspt":[],"pra_ss1_23":["P3.3","P3.4","P-IT.2"],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":["LOG-11"],"csa_aicm":["LOG-11"],"ccss_v9":["1.04.5","1.05.2","2.04.1"],"mica":["Art.63(2)","Art.67(1)","Art.68(1)","Art.69(1)","Art.70(1)","Art.72(1)","Art.82(1)","Art.86(1)","Art.88(1)","Art.92(1)"],"basel_sco60":[],"bssc":["NOS-06"],"sec_custody_digital":["SEC-CD-15"],"dpdpa":["Rules.6(1)(c)"]},"attack_techniques":[],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data 2026-10-03: nist_csf_2 DE.CM-01, DE.CM-09 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"detective","used_by_patterns":["SP-012","SP-028","SP-029","SP-030","SP-031","SP-032","SP-037","SP-041","SP-044","SP-045","SP-046","SP-050","SP-054"]}}