# AU-12 Audit Record Generation

NIST SP 800-53 control. Family: AU Audit and Accountability. Function: detective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2a on [Assignment: organization-defined system components]; b. Allow [Assignment: organization-defined personnel or roles] to select the event types that are to be logged by specific components of the system; and c. Generate audit records for the event types defined in AU-2c that include the audit record content defined in AU-3.
Guidance: Audit records can be generated from many different system components. The event types specified in AU-2d are the event types for which audit logs are to be generated and are a subset of all event types for which the system can generate audit records.

## Enhancements (4)
- AU-12(01) System-wide and Time-correlated Audit Trail. Baselines: high
- AU-12(02) Standardized Formats
- AU-12(03) Changes by Authorized Individuals. Baselines: high
- AU-12(04) Query Parameter Audits of Personally Identifiable Information
Each enhancement's statement: /api/v1/controls/AU-12?fields=enhancements

## Patterns that use it (12)
- Critical (2): SP-031 Security Monitoring and Response; SP-037 Privileged User Management
- Important (8): SP-028 Secure DevOps Pipeline Pattern; SP-029 Zero Trust Architecture; SP-030 API Security; SP-032 Modern Authentication; SP-044 SaaS Identity Lifecycle Management; SP-045 AI Governance and Responsible AI; SP-046 External Attack Surface Management; SP-054 CBDC and Digital Currency Infrastructure (draft)
- Standard (2): SP-012 Secure Software Development Lifecycle; SP-050 Mobile Security Architecture (draft)

## Clauses by framework (61 frameworks)
- iso_27001_2022: 7.5, A.8.15. OSA's own, not in NIST's crosswalk: 7.5
- iso_27002_2022: 8.15
- pci_dss_v4: 10.2
- nist_csf_2: DE.CM-01, DE.CM-03, DE.CM-09, PR.PS-04
- cis_controls_v8: CIS 3.14, CIS 8, CIS 8.2
- finos_ccc: CCC-C04, CCC-C17
- iec_62443: 3-3 SR 2.8
- apra_cps_234: Para 22-23
- bsi_grundschutz: OPS.1.1.5
- anssi: Hygiene.29, SecNumCloud.13.7
- dora: Art.10(1)
- bio2: 8.15
- rbi_csf: Annex1.16, Annex1.17, ITGRCA.15
- fisc: FISC.O2
- hkma_tme1: TME1.4.2, TME1.5.2, TME1.8.2
- mlps_2: 8.1.3.5, 8.1.4.3
- cra: CRA.I.2l
- swift_cscf: SWIFT.6.4
- cbb_tm: TM-12
- cbuae: CR-3
- nca_ecc: 2-12
- qatar_nia: OS
- uae_ia: T7
- bog_cisd: CISD-VII
- bom_ctrm: 4.2
- cbe_csf: CD-1
- cbn_csf: Part3.5
- sa_js2: JS2-7.3
- bcbs_239: Principle 4
- bot_cyber: Ch3.1
- cpmi_pfmi: CG.DE, PFMI.P17
- eba_ict: 3.4.5, 3.5(c)
- ecb_croe: CROE.2.4
- ffiec_is: II.C.15, II.C.18, III.B
- hipaa_sr: §164.308(a)(1)(ii)(D), §164.308(a)(5)(ii)(C), §164.312(b)
- iosco_cyber: DET-1, DET-4
- nydfs_500: 500.6
- sebi_cscrf: DE.AU, DE.DP
- cmmc_2: AU
- nrc_73_54: RG5.71-A-AU
- ieee_1686: 5.2
- pci_pts: L
- tiber_eu: TIBER.BT
- pci_hsm: 6, 8
- common_criteria: CC Part 2 — FAU
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.5
- fda_21_cfr_11: §11.10(e), §11.50
- fda_cyber: SA-5
- hitrust_csf: 09.g
- iso_27799: 9.2, 12.4
- lloyds_ms: MS2.1, MS8.12
- naic_ds: 4-audit, 4B
- pra_ss1_23: P3.3, P3.4, P-IT.2
- csa_ccm_v4: LOG-11
- csa_aicm: LOG-11
- ccss_v9: 1.04.5, 1.05.2, 2.04.1
- mica: Art.63(2), Art.67(1), Art.68(1), Art.69(1), Art.70(1), Art.72(1), Art.82(1), Art.86(1), Art.88(1), Art.92(1)
- bssc: NOS-06
- sec_custody_digital: SEC-CD-15
- dpdpa: Rules.6(1)(c)
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/AU-12
- Clauses only: /api/v1/controls/AU-12?fields=mappings
- Page for people: /controls/au-12/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
