Under active development Content is continuously updated and improved

AU-2Auditable Events

PBMM (P1)
Secret (P1)
Technical

>Control Description

(A) The organization determines that the information system is capable of auditing the following events: organization-defined auditable events. (B) The organization coordinates the security audit function with other organizational entities requiring audit-related information to enhance mutual support and to help guide the selection of auditable events. (C) The organization provides a rationale for why the auditable events are deemed to be adequate to support after-the-fact investigations of security incidents. (D) The organization determines that the following events are to be audited within the information system: organization-defined audited events (the subset of the auditable events defined in AU-2 a.) along with the frequency of (or situation requiring) auditing for each identified event.

>Supplemental Guidance

An event is any observable occurrence in an organizational information system. Organizations identify audit events as those events which are significant and relevant to the security of information systems and the environments in which those systems operate in order to meet specific and ongoing audit needs. Audit events can include, for example, password changes, failed logons, or failed accesses related to information systems, administrative privilege usage, PIV credential usage, or third-party credential usage.

In determining the set of auditable events, organizations consider the auditing appropriate for each of the security controls to be implemented. To balance auditing requirements with other information system needs, this control also requires identifying that subset of auditable events that are audited at a given point in time. For example, organizations may determine that information systems must have the capability to log every file access both successful and unsuccessful, but not activate that capability except for specific circumstances due to the potential burden on system performance.

Auditing requirements, including the need for auditable events, may be referenced in other security controls and control enhancements. Organizations also include auditable events that are required by applicable GC legislation and TBS policies, directives, and standards. Audit records can be generated at various levels of abstraction, including at the packet level as information traverses the network.

Selecting the appropriate level of abstraction is a critical aspect of an audit capability and can facilitate the identification of root causes to problems. Organizations consider in the definition of auditable events, the auditing necessary to cover related events such as the steps in distributed, transaction-based processes (e.g., processes that are distributed across multiple organizations) and actions that occur in service-oriented architectures. Related controls: AC-6, AC-17, AU-3, AU-12, MA-4, MP-2, MP-4, SI-4

>Tailoring Guidance

The information system audits the following privileged user/process events at a minimum: (a) Successful and unsuccessful attempts to access, modify, or delete security objects (Security objects include audit data, system configuration files and file or users’ formal access permissions.) (b) Successful and unsuccessful logon attempts (c) Privileged activities or other system level access (see notes for AU-2 (4)) (d) Starting and ending time for user access to the system (e) Concurrent logons from different workstations (f) All program initiations (see notes for AU-2 (4)) In addition, the information system audits the following unprivileged user/process events at a minimum: (a) Successful and unsuccessful attempts to access, modify, or delete security objects (b) Successful and unsuccessful logon attempts (c) Starting and ending time for user access to the system (d) Concurrent logons from different workstations

>Profile-Specific Parameters

(A) events [Authorizer defined list of auditable events (see Notes and additional requirements column)]

Ask AI

Configure your API key to use AI features.