Audit and Accountability
NIST SP 800-53 Rev 5 Audit and Accountability controls.
Policy and Procedures
Develop, document, and disseminate to [parameter]:
Event Logging
Identify the types of events that the system is capable of logging in support of the audit function: [parameter];
Content of Audit Records
Ensure that audit records contain information that establishes the following:
Audit Log Storage Capacity
Allocate audit log storage capacity to accommodate [parameter].
Response to Audit Logging Process Failures
Alert [parameter] within [parameter] in the event of an audit logging process failure; and
Audit Record Review, Analysis, and Reporting
Review and analyze system audit records [parameter] for indications of [parameter] and the potential impact of the inappropriate or unusual activity;
Audit Record Reduction and Report Generation
Provide and implement an audit record reduction and report generation capability that:
Time Stamps
Use internal system clocks to generate time stamps for audit records; and
Protection of Audit Information
Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and
Non-repudiation
Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [parameter].
Audit Record Retention
Retain audit records for [parameter] to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements.
Audit Record Generation
Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on [parameter];
Monitoring for Information Disclosure
Monitor [parameter] [parameter] for evidence of unauthorized disclosure of organizational information; and
Session Audit
Provide and implement the capability for [parameter] to [parameter] the content of a user session under [parameter] ; and
Alternate Audit Logging Capability
Alternate Audit Logging Capability
Cross-organizational Audit Logging
Employ [parameter] for coordinating [parameter] among external organizations when audit information is transmitted across organizational boundaries.