← Controls / AU

AU-07 Audit Record Reduction and Report Generation

Audit and Accountability

Moderate High

Description

Provide and implement an audit record reduction and report generation capability that: a. Supports on-demand audit record review, analysis, and reporting requirements and after-the-fact investigations of incidents; and b. Does not alter the original content or time ordering of audit records.

Supplemental Guidance

Audit record reduction is a process that manipulates collected audit log information and organizes it into a summary format that is more meaningful to analysts. Audit record reduction and report generation capabilities do not always emanate from the same system or from the same organizational entities that conduct audit logging activities. The audit record reduction capability includes modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. The report generation capability provided by the system can generate customizable reports. Time ordering of audit records can be an issue if the granularity of the timestamp in the record is insufficient.

Changes from Rev 4

Title changed from 'Audit Reduction and Report Generation' Control text changes to include 'implement' Minor additions to discussion

Enhancements (1)

What NIST adds to this control. Select one to read its statement.

AU-07(01) Automatic Processing ModerateHigh

Provide and implement the capability to process, sort, and search audit records for events of interest based on the following content: [Assignment: organization-defined fields within audit records].

Withdrawn by NIST:

  • AU-07(02) Automatic Sort and Search, now in AU-07(01)

Patterns that use this control (3)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ISO 27001:2022

7.5A.8.15

ISO 27002:2022

8.15

CIS Controls v8

CIS 8

NIST CSF 2.0

PR.PS-04RS.AN-03RS.AN-06RS.AN-07

SOC 2 TSC

CC7.2CC7.3

ISO 42001:2023

A.6.2.8

BSI IT-Grundschutz

OPS.1.1.5

ANSSI

Hygiene.29SecNumCloud.13.7

FINMA Circular 2023/1

IV.C(66)IV.C(67)

OSFI B-13

B-13.3.3

EU GDPR

Art.5(2)Art.30(1)

EU DORA

Art.10(1)

BIO2

8.15

RBI CSF

Annex1.16ITGRCA.15

FISC Security Guidelines

FISC.O11

LGPD + BCB 4893

BCB.Art.20

MLPS 2.0

8.1.5.2

NCA ECC

2-12

UAE IA

T7

CBB TM

TM-12

Qatar NIA

IMOS

CBUAE

CR-3

CBE CSF

CD-1

SA JS2

JS2-7.3

CBN CSF

Part3.5

BoG CISD

CISD-VII

BoM CTRM

4.2

IOSCO Cyber Resilience

DET-1

BCBS 239

Principle 7Principle 9

CPMI-IOSCO PFMI

CG.DE

FFIEC IS

III.BIV.A.4

NYDFS 500

500.6

HIPAA Security Rule

§164.308(a)(1)(ii)(D)§164.312(b)

ECB CROE

CROE.2.4

EBA ICT Guidelines

3.4.5

SEBI CSCRF

DE.AU

BOT Cyber Resilience

Ch3.1

CMMC 2.0

AU

Common Criteria

CC Part 2 — FAU

ISAE 3402

Clause 10

Lloyd's Minimum Standards

MS8.12

NAIC Insurance Data Security

4-audit5

PRA SS1/23

P-IT.2

FCA SYSC 13

SYSC 13.7.5

HITRUST CSF v11

09.g

FDA 21 CFR Part 11

§11.10(e)

ISO 27799

12.4

SEC Custody (Digital Assets)

SEC-CD-15

India DPDPA

Rules.6(1)(c)

ISO 17799 (legacy)

10.10.3

COBIT 4.1 (legacy)

None.