Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-172 Enhanced CUI Protection Center

03.03 — Audit and Accountability

Study this CUI requirement family as a connected set of implementation decisions, evidence expectations, and assessment procedures.

4Active requirements
7Parameters
4Assessment objectives

CUI requirement family

Audit and Accountability

Use this family as a planning boundary, but assess every applicable requirement against the real CUI system boundary, inherited services, organization-defined parameters, and operational evidence.

4 active0 withdrawnRevision 3
AU

Family catalog

Requirements and assessment procedures.

Withdrawn records remain available and link to the requirements where their intent was incorporated or addressed.

03.03.01EActive

Protection of Audit Record Storage in Separate Physical Systems or Components

Storing audit records in a repository that is separate from the audited system or system component helps to ensure that a compromise of the system being audited does not also result in a compromise of the audit records. Storing audit records on separate physical systems or components preserves the confidentiality, integrity, and availability of audit records and facilitates the management of audit records as an organ

03.03.02EActive

Real-Time Alerts for Audit Processing Failures

Alerts provide organizations with urgent messages. Real-time alerts provide these messages at information technology speed (i.e., the time from event detection to alert occurs in seconds or less). This requirement enhances SP 800-171 requirement 03.03.04.

03.03.03EActive

Dual Authorization for Audit Information and Actions

Dual authorization is also known as two-person control since it requires the approval of two authorized individuals to reduce the risk related to insider threat when executing audit functions. Dual authorization reduces risks related to insider threats, including adversaries who have obtained credentials. Organizations may choose different selection options for different types of audit information. To reduce the risk

03.03.04EActive

Integrated Analysis of Audit Records

Integrated analysis of audit records requires that the analysis of information generated by scanning, monitoring, or other data collection activities is integrated with the analysis of audit record information. Security information and event management (SIEM) tools can facilitate audit record aggregation or consolidation from multiple system components as well as audit record correlation and analysis. The use of stan