Under active development Content is continuously updated and improved

AU-2Event Logging

>Control Description

a

Identify the types of events that the system is capable of logging in support of the audit function: organization-defined event types that the system is capable of logging;

b

Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged;

c

Specify the following event types for logging within the system: organization-defined event types (subset of the event types defined in AU-2a.) along with the frequency of (or situation requiring) logging for each identified event type;

d

Provide a rationale for why the event types selected for logging are deemed to be adequate to support after-the-fact investigations of incidents; and

e

Review and update the event types selected for logging organization-defined frequency.

>Related Controls

Ask AI

Configure your API key to use AI features.