Security requirement
- a.Include the following content in audit records:
- 1.What type of event occurred
- 2.When the event occurred
- 3.Where the event occurred
- 4.Source of the event
- 5.Outcome of the event
- 6.Identity of the individuals, subjects, objects, or entities associated with the event
- b.Provide additional information for audit records as needed.
Discussion
Audit record content that may be necessary to support the auditing function includes time stamps, source and destination addresses, user or process identifiers, event descriptions, file names, and the access control or flow control rules that are invoked. Event outcomes can include indicators of event success or failure and event-specific results (e.g., the security state of the system after the event occurred). Detailed information that organizations consider in audit records may include a full text recording of privileged commands or the individual identities of group account users.
Implementation perspective
Treat Audit Record Content as a CUI protection outcome that must be reflected in the system boundary, documented implementation, operational behavior, and assessment evidence. Pay particular attention to event selection, trustworthy logging, review, retention, and support for CUI investigations.
- Confirm the requirement is in scope for the CUI system components, services, users, and external connections being assessed.
- Resolve every organization-defined parameter through an approved governance and tailoring process.
- Map each clause of the requirement to an accountable owner, implementation mechanism, and evidence source.
- Verify that inherited and shared implementations are supported by current provider evidence and responsibility boundaries.
- Collect evidence during normal operation and review changes, exceptions, and deficiencies on a risk-based cadence.
Questions to ask
- Which CUI assets, data flows, users, and services are protected by this requirement?
- Which portions are implemented locally, inherited, shared, or not applicable, and what evidence supports that determination?
- Do the system security plan, deployed configuration, operating process, and assessment evidence tell the same story?
- What change, incident, or threshold should trigger reassessment?
Evidence and validation
- logging standards and event-selection decisions
- sample audit records and retention settings
- time synchronization evidence
- alert review and investigation records
Common failure patterns
- collecting logs without defined use cases
- critical CUI events absent from the audit trail
- retention shorter than investigative needs
- logs modifiable by the same administrators being monitored
Assessment objectives and methods
Assessment objectives (7)
- a.1.
audit records contain information that establishes what type of event occurred.
- a.2.
audit records contain information that establishes when the event occurred.
- a.3.
audit records contain information that establishes where the event occurred.
- a.4.
audit records contain information that establishes the source of the event.
- a.5.
audit records contain information that establishes the outcome of the event.
- a.6.
audit records contain information that establishes the identity of the individuals, subjects, objects, or entities associated with the event.
- b.
additional information for audit records is provided, as needed.
Examine
- audit and accountability policy and procedures
- procedures for the content of audit records
- list of organization-defined auditable events
- system design documentation
- system configuration settings
- system audit records
- system incident reports
- system security plan
- other relevant documents or records
Interview
- personnel with audit and accountability responsibilities
- personnel with information security responsibilities
- system developers
- system administrators
Test
- mechanisms for implementing system auditing of auditable events
- system audit capability
Source NIST SP 800-53 controls
These controls are referenced by the official SP 800-171 Rev. 3 OSCAL record. Open the corresponding control pages for complete control text, enhancements, D3FEND mappings, and related learning.
Authoritative sources
- NIST SP 800-171 Revision 3 official publication ↗
- NIST SP 800-171A Revision 3 official publication ↗
- NIST OSCAL Content release used for this import ↗
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. The official publications, the responsible federal agency, and the governing contract or agreement determine applicability, tailoring, assessment depth, and required implementation.