← Controls / AU

AU-02 Event Logging

Audit and Accountability

Low Moderate High Privacy

Description

a. Identify the types of events that the system is capable of logging in support of the audit function: [Assignment: organization-defined event types that the system is capable of logging]; b. Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged; c. Specify the following event types for logging within the system: [Assignment: organization-defined event types (subset of the event types defined in AU-02a.) along with the frequency of (or situation requiring) logging for each identified event type]; d. Provide a rationale for why the event types selected for logging are deemed to be adequate to support after-the-fact investigations of incidents; and e. Review and update the event types selected for logging [Assignment: organization-defined frequency].

Supplemental Guidance

An event is an observable occurrence in a system. The types of events that require logging are those events that are significant and relevant to the security of systems and the privacy of individuals. Event logging also supports specific monitoring and auditing needs. Event types include password changes, failed logons or failed accesses related to systems, security or privacy attribute changes, administrative privilege usage, PIV credential usage, data action changes, query parameters, or external credential usage. In determining the set of event types that require logging, organizations consider the monitoring and auditing appropriate for each of the controls to be implemented. For completeness, event logging includes all protocols that are operational and supported by the system. To balance monitoring and auditing requirements with other system needs, event logging requires identifying the subset of event types that are logged at a given point in time. For example, organizations may determine that systems need the capability to log every file access successful and unsuccessful, but not activate that capability except for specific circumstances due to the potential burden on system performance. The types of events that organizations desire to be logged may change. Reviewing and updating the set of logged events is necessary to help ensure that the events remain relevant and continue to support the needs of the organization. Organizations consider how the types of logging events can reveal information about individuals that may give rise to privacy risk and how best to mitigate such risks. For example, there is the potential to reveal personally identifiable information in the audit trail, especially if the logging event is based on patterns or time of usage. Event logging requirements, including the need to log specific event types, may be referenced in other controls and control enhancements. These include AC-2(4), AC-3(10), AC-6(9), AC-17(1), CM-3f, CM-5(1), IA-3(3)(b), MA-4(1), MP-4(2), PE-3, PM-21, PT-7, RA-8, SC-7(9), SC-7(15), SI-3(8), SI-4(22), SI-7(8), and SI-10(1). Organizations include event types that are required by applicable laws, executive orders, directives, policies, regulations, standards, and guidelines. Audit records can be generated at various levels, including at the packet level as information traverses the network. Selecting the appropriate level of event logging is an important part of a monitoring and auditing capability and can identify the root causes of problems. When defining event types, organizations consider the logging necessary to cover related event types, such as the steps in distributed, transaction-based processes and the actions that occur in service-oriented architectures.

Changes from Rev 4

Title changed for 'Audit Events' Changes parameter regarding the specific types of events that the system is capable of logging Requires the review and update the event types selected for logging at a specific frequency Incorporates withdrawn control AU-02(3) Incorporates audit elements of withdrawn App J control UL-02

Enhancements (0)

NIST has withdrawn every enhancement this control had.

  • AU-02(01) Compilation of Audit Records from Multiple Sources, now in AU-12
  • AU-02(02) Selection of Audit Events by Component, now in AU-12
  • AU-02(03) Reviews and Updates, now in AU-02
  • AU-02(04) Privileged Functions, now in AC-06(09)

Compliance Mappings

ISO 27001:2022

7.5A.8.15

ISO 27002:2022

8.15

COBIT 2019

DSS06

CIS Controls v8

CIS 3.14CIS 8CIS 8.1CIS 8.2CIS 8.6CIS 8.7CIS 8.8CIS 8.12

NIST CSF 2.0

PR.PS-04

SOC 2 TSC

CC6.1-POF7CC6.7-POF1CC7.1CC7.1-POF1CC7.2CC7.2-POF1CC7.3CC8.1PI1.4

PCI DSS v4.0.1

10.2

CSA CCM v4

CEK-09LOG-01LOG-07LOG-08LOG-10LOG-11LOG-12

CSA AICM v1

CEK-09DSP-24LOG-01LOG-07LOG-08LOG-10LOG-11LOG-12LOG-14LOG-15

FINOS CCC

CCC-C04CCC-C17

ISO 42001:2023

A.6.2.8

IEC 62443

3-3 SR 2.8

MAS TRM

15

APRA CPS 234

Para 22-23

ASD Essential Eight

E8-1 ML2

BSI IT-Grundschutz

OPS.1.1.5

ANSSI

Hygiene.29SecNumCloud.13.7

FINMA Circular 2023/1

IV.C(66)IV.C(67)IV.C(68)

OSFI B-13

B-13.3.3

EU GDPR

Art.5(2)Art.7(1)Art.30(1)(g)Art.33(3)

EU DORA

Art.10(1)Art.10(2)

BIO2

8.15

RBI CSF

Annex1.16Annex1.17ITGRCA.15

FISC Security Guidelines

FISC.O2FISC.O7FISC.O11FISC.T11

LGPD + BCB 4893

BCB.Art.6BCB.Art.20LGPD.Art.6LGPD.Art.8LGPD.Art.42-45

HKMA TM-E-1

TME1.4.2TME1.5.2TME1.8.2TME1.10.3TME1.11.2

MLPS 2.0

8.1.3.58.1.4.38.1.5.18.2

EU CRA

CRA.I.2dCRA.I.2l

SWIFT CSCF

SWIFT.1.2SWIFT.2.9SWIFT.5.4SWIFT.6.4

NCA ECC

2-12

UAE IA

T7

CBB TM

TM-12

Qatar NIA

OS

CBUAE

CR-3

CBE CSF

CD-1CTO-5

SA JS2

JS2-7.3

CBN CSF

Part3.5

BoG CISD

CISD-VII

POPIA

s8s17s19

BoM CTRM

3.134.2

IOSCO Cyber Resilience

DET-1

BCBS 239

Principle 3Principle 4

CPMI-IOSCO PFMI

CG.DEPFMI.P17

FFIEC IS

II.C.15II.C.18III.B

NYDFS 500

500.6

HIPAA Security Rule

§164.308(a)(1)(ii)(D)§164.308(a)(5)(ii)(C)§164.312(b)

ECB CROE

CROE.2.4

EBA ICT Guidelines

3.4.53.5(c)

SEBI CSCRF

DE.AU

BOT Cyber Resilience

Ch3.1Ch6.1

CMMC 2.0

AU

NERC CIP

CIP-007-6

10 CFR 73.54

RG5.71-A-AU

TSA Pipeline SD

SD-2 Sec C

IEEE 1686-2022

5.2

DOE C2M2 v2.1

SITUATION

API 1164

Sec 9

AWIA

AWWA Sec 5

IAEA NSS 17-T

Sec 5.5

PCI PTS v6

L

TIBER-EU

TIBER.BT

PCI HSM

68

Common Criteria

CC Part 2 — FAU

ISAE 3402

Clause 4

Solvency II

Pillar3-Reporting

Lloyd's Minimum Standards

MS2.1MS5.1MS8.12MS13.2

NAIC Insurance Data Security

4-audit4B

PRA SS1/23

P3.2P3.4P4.3P4.4P-IT.2

FCA SYSC 13

SYSC 13.7.5

HITRUST CSF v11

09.g

FDA 21 CFR Part 11

§11.10(e)§11.50

FDA Cybersecurity Guidance

SA-5

ISO 27799

9.212.4H.4H.5

OWASP MASVS v2.1

MASVS-STORAGE-2

CCSS v9.0

1.05.22.04.1

MiCA

Art.68(1)Art.69(1)Art.70(1)Art.72(1)Art.86(1)Art.88(1)Art.92(1)

Basel SCO60

SCO60.50SCO60.55SCO60.62SCO60.66SCO60.73

BSSC Standards

GSP-10GSP-12NOS-06

SEC Custody (Digital Assets)

SEC-CD-04SEC-CD-05SEC-CD-07SEC-CD-13SEC-CD-15SEC-CD-18SEC-CD-20

India DPDPA

Rules.6(1)(c)

ISO 17799 (legacy)

10.10.1

COBIT 4.1 (legacy)

AI2.3