← Controls / AU

AU-05 Response to Audit Logging Process Failures

Audit and Accountability

Low Moderate High

Description

a. Alert [Assignment: organization-defined personnel or roles] within [Assignment: organization-defined time period] in the event of an audit logging process failure; and b. Take the following additional actions: [Assignment: organization-defined additional actions].

Supplemental Guidance

Audit logging process failures include software and hardware errors, failures in audit log capturing mechanisms, and reaching or exceeding audit log storage capacity. Organization-defined actions include overwriting oldest audit records, shutting down the system, and stopping the generation of audit records. Organizations may choose to define additional actions for audit logging process failures based on the type of failure, the location of the failure, the severity of the failure, or a combination of such factors. When the audit logging process failure is related to storage, the response is carried out for the audit log storage repository (i.e., the distinct system component where the audit logs are stored), the system on which the audit logs reside, the total audit log storage capacity of the organization (i.e., all audit log storage repositories combined), or all three. Organizations may decide to take no additional actions after alerting designated roles or personnel.

Changes from Rev 4

Title changed from ‘Response to Audit Processing Failures' Adds parameter text to alert within a specific time period Discussion added regarding audit logging process failure related to storage

Enhancements (5)

What NIST adds to this control. Select one to read its statement.

AU-05(01) Storage Capacity Warning High

Provide a warning to [Assignment: organization-defined personnel, roles, and/or locations] within [Assignment: organization-defined time period] when allocated audit log storage volume reaches [Assignment: organization-defined percentage] of repository maximum audit log storage capacity.

AU-05(02) Real-time Alerts High

Provide an alert within [Assignment: organization-defined real-time period] to [Assignment: organization-defined personnel, roles, and/or locations] when the following audit failure events occur: [Assignment: organization-defined audit logging failure events requiring real-time alerts].

AU-05(03) Configurable Traffic Volume Thresholds

Enforce configurable network communications traffic volume thresholds reflecting limits on audit log storage capacity and [Selection: reject; delay] network traffic above those thresholds.

AU-05(04) Shutdown on Failure

Invoke a [Selection (one): full system shutdown; partial system shutdown; degraded operational mode with limited mission or business functionality available] in the event of [Assignment: organization-defined audit logging failures], unless an alternate audit logging capability exists.

AU-05(05) Alternate Audit Logging Capability

Provide an alternate audit logging capability in the event of a failure in primary audit logging capability that implements [Assignment: organization-defined alternate audit logging functionality].

Patterns that use this control (4)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

7.5A.8.15

ISO 27002:2022

8.15

CIS Controls v8

CIS 8

PCI DSS v4.0.1

10.7

CSA CCM v4

LOG-13

CSA AICM v1

LOG-13

IEC 62443

3-3 SR 2.9

BSI IT-Grundschutz

OPS.1.1.5

ANSSI

Hygiene.29SecNumCloud.13.7

FINMA Circular 2023/1

IV.A(41)IV.C(66)IV.C(67)

OSFI B-13

B-13.3.3

EU GDPR

Art.32(1)(b)Art.32(1)(d)

EU DORA

Art.10(1)Art.10(2)

BIO2

8.15

RBI CSF

Annex1.16ITGRCA.15

FISC Security Guidelines

FISC.O11

EU CRA

CRA.I.2l

NCA ECC

2-12

UAE IA

T7

CBB TM

TM-12

Qatar NIA

OS

CBUAE

CR-3

CBE CSF

CD-1

SA JS2

JS2-7.3

CBN CSF

Part3.5

BoG CISD

CISD-VII

BoM CTRM

4.2

IOSCO Cyber Resilience

DET-1

BCBS 239

Principle 5

CPMI-IOSCO PFMI

CG.DE

FFIEC IS

III.B

NYDFS 500

500.6

HIPAA Security Rule

§164.312(b)

ECB CROE

CROE.2.4

EBA ICT Guidelines

3.4.5

SEBI CSCRF

DE.AU

CMMC 2.0

AU

10 CFR 73.54

RG5.71-A-AU

Common Criteria

CC Part 2 — FAU

Lloyd's Minimum Standards

MS8.12

NAIC Insurance Data Security

4-audit

PRA SS1/23

P5.3

HITRUST CSF v11

09.g

FDA 21 CFR Part 11

§11.10(e)

FDA Cybersecurity Guidance

SA-5

ISO 27799

12.4

SEC Custody (Digital Assets)

SEC-CD-15

ISO 17799 (legacy)

10.10.3

COBIT 4.1 (legacy)

None.