# AU-04 Audit Log Storage Capacity

NIST SP 800-53 control. Family: AU Audit and Accountability. Function: detective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: Allocate audit log storage capacity to accommodate [Assignment: organization-defined audit log retention requirements].
Guidance: Organizations consider the types of audit logging to be performed and the audit log processing requirements when allocating audit log storage capacity. Allocating sufficient audit log storage capacity reduces the likelihood of such capacity being exceeded and resulting in the potential loss or reduction of audit logging capability.

## Enhancements (1)
- AU-04(01) Transfer to Alternate Storage
Each enhancement's statement: /api/v1/controls/AU-04?fields=enhancements

## Patterns that use it (5)
- Critical (1): SP-019 Secure Ad-Hoc File Exchange Pattern
- Important (1): SP-031 Security Monitoring and Response
- Standard (3): SP-001 Client Module; SP-002 Server Module; SP-016 DMZ Module

## Clauses by framework (50 frameworks)
- iso_27001_2022: 7.5, A.8.6, A.8.15. OSA's own, not in NIST's crosswalk: 7.5, A.8.15
- iso_27002_2022: 8.6, 8.15
- cobit_2019: BAI04
- nist_csf_2: PR.IR-04. OSA's own, not in NIST's crosswalk: PR.IR-04
- cis_controls_v8: CIS 8, CIS 8.3
- iec_62443: 3-3 SR 2.9, 3-3 SR 7.2
- bsi_grundschutz: OPS.1.1.5
- anssi: Hygiene.29, SecNumCloud.13.7
- osfi_b13: B-13.3.3
- finma_circular: IV.A(28), IV.A(29), IV.C(66)
- gdpr: Art.5(1)(e), Art.30(1)
- dora: Art.10(1)
- bio2: 8.6, 8.15
- rbi_csf: Annex1.16, ITGRCA.15
- fisc: FISC.O11, FISC.O13
- lgpd_bcb: BCB.Art.9, BCB.Art.20
- hkma_tme1: TME1.5.2, TME1.5.3
- dnb_good_practice: DNB.18.1
- cra: CRA.I.2l
- cbb_tm: TM-5, TM-12
- cbuae: CR-3
- nca_ecc: 2-12
- qatar_nia: OS
- uae_ia: T7
- bog_cisd: CISD-VII
- bom_ctrm: 4.2
- cbe_csf: CD-1
- cbn_csf: Part3.5
- sa_js2: JS2-7.3
- bcbs_239: Principle 5
- bot_cyber: Ch3.1
- cpmi_pfmi: CG.DE
- eba_ict: 3.4.5
- ecb_croe: CROE.2.4
- ffiec_is: III.B
- hipaa_sr: §164.312(b)
- iosco_cyber: DET-1
- nydfs_500: 500.6
- sebi_cscrf: DE.AU
- cmmc_2: AU
- nrc_73_54: RG5.71-A-AU
- ieee_1686: 5.2
- common_criteria: CC Part 2 — FAU
- fda_21_cfr_11: §11.10(e)
- fda_cyber: SA-5
- hitrust_csf: 09.g
- iso_27799: 12.4
- lloyds_ms: MS8.12
- naic_ds: 4-audit
- sec_custody_digital: SEC-CD-15
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AU-04
- Clauses only: /api/v1/controls/AU-04?fields=mappings
- Page for people: /controls/au-04/
