AU-09 Protection of Audit Information
Audit and Accountability
Description
a. Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and b. Alert [Assignment: organization-defined personnel or roles] upon detection of unauthorized access, modification, or deletion of audit information.
Supplemental Guidance
Audit information includes all information needed to successfully audit system activity, such as audit records, audit log settings, audit reports, and personally identifiable information. Audit logging tools are those programs and devices used to conduct system audit and logging activities. Protection of audit information focuses on technical protection and limits the ability to access and execute audit logging tools to authorized individuals. Physical protection of audit information is addressed by both media protection controls and physical and environmental protection controls.
Changes from Rev 4
Adds new alert for specified individuals or roles upon detection of unauthorized access, modification, or deletion of audit information New parameter supports specifying the individuals or roles to receive alerts Discussion reference to PII
Enhancements (7)
What NIST adds to this control. Select one to read its statement.
AU-09(01) Hardware Write-once Media
Write audit trails to hardware-enforced, write-once media.
AU-09(02) Store on Separate Physical Systems or Components High
Store audit records [Assignment: organization-defined frequency] in a repository that is part of a physically different system or system component than the system or component being audited.
AU-09(03) Cryptographic Protection High
Implement cryptographic mechanisms to protect the integrity of audit information and audit tools.
AU-09(04) Access by Subset of Privileged Users ModerateHigh
Authorize access to management of audit logging functionality to only [Assignment: organization-defined subset of privileged users or roles].
AU-09(05) Dual Authorization
Enforce dual authorization for [Selection (one or more): movement; deletion] of [Assignment: organization-defined audit information].
AU-09(06) Read-only Access
Authorize read-only access to audit information to [Assignment: organization-defined subset of privileged users or roles].
AU-09(07) Store on Component with Different Operating System
Store audit information on a component running a different operating system than the system or component being audited.
Patterns that use this control (13)
Grouped by the emphasis each pattern gives it.