# AU-09 Protection of Audit Information

NIST SP 800-53 control. Family: AU Audit and Accountability. Function: preventative. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and b. Alert [Assignment: organization-defined personnel or roles] upon detection of unauthorized access, modification, or deletion of audit information.
Guidance: Audit information includes all information needed to successfully audit system activity, such as audit records, audit log settings, audit reports, and personally identifiable information. Audit logging tools are those programs and devices used to conduct system audit and logging activities. Protection of audit information focuses on technical protection and limits the ability to access and execute audit logging tools to authorized individuals. Physical protection of audit information is addressed by both media protection controls and physical and environmental protection controls.

## Enhancements (7)
- AU-09(01) Hardware Write-once Media
- AU-09(02) Store on Separate Physical Systems or Components. Baselines: high
- AU-09(03) Cryptographic Protection. Baselines: high
- AU-09(04) Access by Subset of Privileged Users. Baselines: moderate, high
- AU-09(05) Dual Authorization
- AU-09(06) Read-only Access
- AU-09(07) Store on Component with Different Operating System
Each enhancement's statement: /api/v1/controls/AU-09?fields=enhancements

## Patterns that use it (13)
- Critical (3): SP-031 Security Monitoring and Response; SP-036 Incident Response; SP-054 CBDC and Digital Currency Infrastructure (draft)
- Important (8): SP-001 Client Module; SP-002 Server Module; SP-016 DMZ Module; SP-022 Board of Directors Room; SP-025 Advanced Monitoring and Detection; SP-026 PCI Full Environment; SP-029 Zero Trust Architecture; SP-053 Zero-Knowledge Proof Architecture (draft)
- Standard (2): SP-021 Realtime Collaboration Pattern; SP-033 Passkey Authentication

## Clauses by framework (65 frameworks)
- iso_27001_2022: 7.5, A.5.33, A.8.15. OSA's own, not in NIST's crosswalk: 7.5
- iso_27002_2022: 5.28, 5.33, 8.15
- pci_dss_v4: 10.3
- nist_csf_2: PR.DS-10, RS.AN-06, RS.AN-07. OSA's own, not in NIST's crosswalk: RS.AN-06, RS.AN-07
- cis_controls_v8: CIS 8
- soc2_tsc: PI1.4, PI1.5
- iso_42001_2023: A.6.2.8
- iec_62443: 3-3 SR 6.1
- apra_cps_234: Para 22-23
- bsi_grundschutz: OPS.1.1.5
- anssi: Hygiene.29, SecNumCloud.13.7
- osfi_b13: B-13.3.2, B-13.3.3
- finma_circular: IV.B.d(59), IV.C(66), IV.C(67)
- gdpr: Art.5(1)(f), Art.32(1)(b)
- dora: Art.10(1)
- bio2: 5.28, 5.33, 8.15
- rbi_csf: Annex1.16, ITGRCA.15
- fisc: FISC.O11
- lgpd_bcb: BCB.Art.3, BCB.Art.9, BCB.Art.15, BCB.Art.20, LGPD.Art.46
- mlps_2: 8.1.3.5, 8.1.4.3, 8.1.5.2
- dnb_good_practice: DNB.20.1
- cra: CRA.I.2f, CRA.I.2l
- swift_cscf: SWIFT.6.4
- cbb_tm: TM-12
- cbuae: CR-3
- nca_ecc: 2-12
- qatar_nia: OS
- uae_ia: T7
- bog_cisd: CISD-VII
- bom_ctrm: 4.2
- cbe_csf: CD-1
- cbn_csf: Part3.5
- popia: s19
- sa_js2: JS2-7.3
- bot_cyber: Ch3.1
- cpmi_pfmi: CG.DE
- eba_ict: 3.4.5, 3.5(c)
- ecb_croe: CROE.2.4
- ffiec_is: III.B
- hipaa_sr: §164.308(a)(1)(ii)(D), §164.312(b)
- iosco_cyber: DET-1
- nydfs_500: 500.6
- sebi_cscrf: DE.AU, RS.AN
- cmmc_2: AU
- nrc_73_54: RG5.71-A-AU
- ieee_1686: 5.2
- iaea_nss: Sec 5.5
- pci_pts: L
- common_criteria: CC Part 2 — FAU
- fca_sysc_13: SYSC 13.G.4
- fda_21_cfr_11: §11.10(b), §11.10(e)
- fda_cyber: SA-5
- hitrust_csf: 09.g, 11.c
- iso_27799: 12.4
- lloyds_ms: MS8.12
- naic_ds: 4-audit, 7
- pra_ss1_23: P-IT.2
- solvency_ii: Pillar3-Reporting
- csa_ccm_v4: IAM-12, LOG-02, LOG-04, LOG-09
- csa_aicm: IAM-12, LOG-02, LOG-04, LOG-09
- ccss_v9: 1.04.5, 1.05.2, 2.04.1, 2.04.2, 2.04.3
- mica: Art.63(2), Art.82(1)
- basel_sco60: SCO60.23, SCO60.62, SCO60.66
- bssc: GSP-12, KMS-09, TIS-07
- sec_custody_digital: SEC-CD-05, SEC-CD-15, SEC-CD-16
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AU-09
- Clauses only: /api/v1/controls/AU-09?fields=mappings
- Page for people: /controls/au-09/
