Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

NIST SP 800-53 Learning Center

AU-12 — Audit Record Generation

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

4Enhancements
2Parameters
3Baseline memberships
3Assessment methods

AU — Audit and Accountability · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on [Organization-defined: system components];
  2. b.Allow [Organization-defined: personnel or roles] to select the event types that are to be logged by specific components of the system; and
  3. c.Generate audit records for the event types defined in [AU-2c](#au-2_smt.c) that include the audit record content defined in [AU-3](#au-3).
Official NIST discussion

Discussion

Audit records can be generated from many different system components. The event types specified in [AU-2d](#au-2_smt.d) are the event types for which audit logs are to be generated and are a subset of all event types for which the system can generate audit records.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

system componentssystem components that provide an audit record generation capability for the events types (defined in AU-02_ODP[02]) are defined;
personnel or rolespersonnel or roles allowed to select the event types that are to be logged by specific components of the system is/are defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Audit Record Generation as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to audit event design, trustworthy collection, retention, review, and investigation support.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • logging standards and event-selection decisions
  • sample audit records and retention settings
  • time-synchronization evidence
  • alert and review records

Common failure patterns

  • collecting logs without defined use cases
  • critical events missing from the audit trail
  • retention shorter than investigative needs
  • logs accessible to the same administrators being monitored

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. AU-12a.audit record generation capability for the event types the system is capable of auditing (defined in AU-02_ODP[01]) is provided by [Organization-defined: system components];
  2. AU-12b.[Organization-defined: personnel or roles] is/are allowed to select the event types that are to be logged by specific components of the system;
  3. AU-12c.audit records for the event types defined in AU-02_ODP[02] that include the audit record content defined in AU-03 are generated.

Examine

  • Audit and accountability policy
  • procedures addressing audit record generation
  • system security plan
  • privacy plan
  • system design documentation
  • system configuration settings and associated documentation
  • list of auditable events
  • system audit records
  • other relevant documents or records

Interview

  • Organizational personnel with audit record generation responsibilities
  • organizational personnel with information security and privacy responsibilities
  • system/network administrators
  • system developers

Test

  • Mechanisms implementing audit record generation capability
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

Official CUI requirement crosswalk

Related NIST SP 800-171 requirements

These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

AU-12(1) — System-wide and Time-correlated Audit Trail

High

Compile audit records from [Organization-defined: system components] into a system-wide (logical or physical) audit trail that is time-correlated to within [Organization-defined: level of tolerance].

Official discussion

Audit trails are time-correlated if the time stamps in the individual audit records can be reliably related to the time stamps in other audit records to achieve a time ordering of the records within organizational tolerances.

Organization-defined parameters (2)
system componentssystem components from which audit records are to be compiled into a system-wide (logical or physical) audit trail are defined;
level of tolerancelevel of tolerance for the relationship between timestamps of individual records in the audit trail is defined;
Assessment objectives and methods

audit records from [Organization-defined: system components] are compiled into a system-wide (logical or physical) audit trail that is time-correlated to within [Organization-defined: level of tolerance].

Examine

  • Audit and accountability policy
  • system security plan
  • privacy plan
  • procedures addressing audit record generation
  • system design documentation
  • system configuration settings and associated documentation
  • system-wide audit trail (logical or physical)
  • system audit records
  • other relevant documents or records

Interview

  • Organizational personnel with audit record generation responsibilities
  • organizational personnel with information security and privacy responsibilities
  • system/network administrators
  • system developers

Test

  • Mechanisms implementing audit record generation capability
Related controls
Official NIST control enhancement

AU-12(2) — Standardized Formats

Produce a system-wide (logical or physical) audit trail composed of audit records in a standardized format.

Official discussion

Audit records that follow common standards promote interoperability and information exchange between devices and systems. Promoting interoperability and information exchange facilitates the production of event information that can be readily analyzed and correlated. If logging mechanisms do not conform to standardized formats, systems may convert individual audit records into standardized formats when compiling system-wide audit trails.

Assessment objectives and methods

a system-wide (logical or physical) audit trail composed of audit records is produced in a standardized format.

Examine

  • Audit and accountability policy
  • system security plan
  • privacy plan
  • procedures addressing audit record generation
  • system design documentation
  • system configuration settings and associated documentation
  • system-wide audit trail (logical or physical)
  • system audit records
  • other relevant documents or records

Interview

  • Organizational personnel with audit record generation responsibilities
  • organizational personnel with security responsibilities
  • system/network administrators
  • system developers

Test

  • Mechanisms implementing audit record generation capability
Official NIST control enhancement

AU-12(3) — Changes by Authorized Individuals

High

Provide and implement the capability for [Organization-defined: individuals or roles] to change the logging to be performed on [Organization-defined: system components] based on [Organization-defined: selectable event criteria] within [Organization-defined: time thresholds].

Official discussion

Permitting authorized individuals to make changes to system logging enables organizations to extend or limit logging as necessary to meet organizational requirements. Logging that is limited to conserve system resources may be extended (either temporarily or permanently) to address certain threat situations. In addition, logging may be limited to a specific set of event types to facilitate audit reduction, analysis, and reporting. Organizations can establish time thresholds in which logging actions are changed (e.g., near real-time, within minutes, or within hours).

Organization-defined parameters (4)
individuals or rolesindividuals or roles authorized to change the logging on system components are defined;
system componentssystem components on which logging is to be performed are defined;
selectable event criteriaselectable event criteria with which change logging is to be performed are defined;
time thresholdstime thresholds in which logging actions are to change is defined;
Assessment objectives and methods
  1. AU-12(03)[01]the capability for [Organization-defined: individuals or roles] to change the logging to be performed on [Organization-defined: system components] based on [Organization-defined: selectable event criteria] within [Organization-defined: time thresholds] is provided;
  2. AU-12(03)[02]the capability for [Organization-defined: individuals or roles] to change the logging to be performed on [Organization-defined: system components] based on [Organization-defined: selectable event criteria] within [Organization-defined: time thresholds] is implemented.

Examine

  • Audit and accountability policy
  • system security plan
  • privacy plan
  • procedures addressing audit record generation
  • system design documentation
  • system configuration settings and associated documentation
  • system-generated list of individuals or roles authorized to change auditing to be performed
  • system audit records
  • other relevant documents or records

Interview

  • Organizational personnel with audit record generation responsibilities
  • organizational personnel with information security and privacy responsibilities
  • system/network administrators
  • system developers

Test

  • Mechanisms implementing audit record generation capability
Related controls
Official NIST control enhancement

AU-12(4) — Query Parameter Audits of Personally Identifiable Information

Provide and implement the capability for auditing the parameters of user query events for data sets containing personally identifiable information.

Official discussion

Query parameters are explicit criteria that an individual or automated system submits to a system to retrieve data. Auditing of query parameters for datasets that contain personally identifiable information augments the capability of an organization to track and understand the access, usage, or sharing of personally identifiable information by authorized personnel.

Assessment objectives and methods
  1. AU-12(04)[01]the capability to audit the parameters of user query events for data sets containing personally identifiable information is provided;
  2. AU-12(04)[02]the capability to audit the parameters of user query events for data sets containing personally identifiable information is implemented.

Examine

  • Audit and accountability policy
  • system security plan
  • privacy plan
  • procedures addressing audit record generation
  • query event records
  • system design documentation
  • system configuration settings and associated documentation
  • map of system data actions
  • system audit records
  • other relevant documents or records

Interview

  • Organizational personnel with audit record generation responsibilities
  • organizational personnel with information security and privacy responsibilities
  • system/network administrators
  • system developers

Test

  • Mechanisms implementing audit record generation capability
Source record

Authoritative sources