AU-12—Audit Generation
PBMM (P1)
Secret (P1)
Technical
>Control Description
(A) The information system provides audit record generation capability for the auditable events defined in AU-2 a. at ⚙organization-defined information system components. (B) The information system allows ⚙organization-defined personnel or roles to select which auditable events are to be audited by specific components of the information system. (C) The information system generates audit records for the events defined in AU-2 d. with the content defined in AU-3.
>Supplemental Guidance
Audit records can be generated from many different information system components. The list of audited events is the set of events for which audits are to be generated. These events are typically a subset of all events for which the information system is capable of generating audit records.
Related controls: AC-3, AU-2, AU-3, AU-6, AU-7
>Tailoring Guidance
In order to facilitate audit review and analysis, audit records should be time correlated and provided in a common format. Time correlation can be achieved by synchronizing the clocks of the systems generating the audit events.
>Profile-Specific Parameters
(A) components [Authorizer defined components]
Ask AI
Configure your API key to use AI features.