Control statement
- a.Review and analyze system audit records [Organization-defined: frequency] for indications of [Organization-defined: inappropriate or unusual activity] and the potential impact of the inappropriate or unusual activity;
- b.Report findings to [Organization-defined: personnel or roles] ; and
- c.Adjust the level of audit record review, analysis, and reporting within the system when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information.
Discussion
Audit record review, analysis, and reporting covers information security- and privacy-related logging performed by organizations, including logging that results from the monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, use of maintenance tools and non-local maintenance, physical access, temperature and humidity, equipment delivery and removal, communications at system interfaces, and use of mobile code or Voice over Internet Protocol (VoIP). Findings can be reported to organizational entities that include the incident response team, help desk, and security or privacy offices. If organizations are prohibited from reviewing and analyzing audit records or unable to conduct such activities, the review or analysis may be carried out by other organizations granted such authority. The frequency, scope, and/or depth of the audit record review, analysis, and reporting may be adjusted to meet organizational needs based on new information received.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Audit Record Review, Analysis, and Reporting as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to audit event design, trustworthy collection, retention, review, and investigation support.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- logging standards and event-selection decisions
- sample audit records and retention settings
- time-synchronization evidence
- alert and review records
Common failure patterns
- collecting logs without defined use cases
- critical events missing from the audit trail
- retention shorter than investigative needs
- logs accessible to the same administrators being monitored
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- AU-06a.system audit records are reviewed and analyzed [Organization-defined: frequency] for indications of [Organization-defined: inappropriate or unusual activity] and the potential impact of the inappropriate or unusual activity;
- AU-06b.findings are reported to [Organization-defined: personnel or roles];
- AU-06c.the level of audit record review, analysis, and reporting within the system is adjusted when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information.
Examine
- Audit and accountability policy
- system security plan
- privacy plan
- procedures addressing audit review, analysis, and reporting
- reports of audit findings
- records of actions taken in response to reviews/analyses of audit records
- other relevant documents or records
Interview
- Organizational personnel with audit review, analysis, and reporting responsibilities
- organizational personnel with information security and privacy responsibilities
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related NIST SP 800-171 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Related NIST SP 800-172 requirements
These Rev. 3 requirements cite this base control or one of its enhancements as a source. The relationship does not by itself determine contractual applicability or complete implementation.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
AU-6(1) — Automated Process Integration
Integrate audit record review, analysis, and reporting processes using [Organization-defined: automated mechanisms].
Official discussion
Organizational processes that benefit from integrated audit record review, analysis, and reporting include incident response, continuous monitoring, contingency planning, investigation and response to suspicious activities, and Inspector General audits.
Organization-defined parameters (1)
Assessment objectives and methods
audit record review, analysis, and reporting processes are integrated using [Organization-defined: automated mechanisms].
Examine
- Audit and accountability policy
- system security plan
- privacy plan
- procedures addressing audit review, analysis, and reporting
- procedures addressing investigation and response to suspicious activities
- system design documentation
- system configuration settings and associated documentation
- system audit records
- other relevant documents or records
Interview
- Organizational personnel with audit review, analysis, and reporting responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Automated mechanisms integrating audit review, analysis, and reporting processes
Related controls
AU-6(2) — Automated Security Alerts
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
AU-6(3) — Correlate Audit Record Repositories
Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.
Official discussion
Organization-wide situational awareness includes awareness across all three levels of risk management (i.e., organizational level, mission/business process level, and information system level) and supports cross-organization awareness.
Assessment objectives and methods
audit records across different repositories are analyzed and correlated to gain organization-wide situational awareness.
Examine
- Audit and accountability policy
- system security plan
- privacy plan
- procedures addressing audit review, analysis, and reporting
- system design documentation
- system configuration settings and associated documentation
- system audit records across different repositories
- other relevant documents or records
Interview
- Organizational personnel with audit review, analysis, and reporting responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms supporting the analysis and correlation of audit records
Related controls
AU-6(4) — Central Review and Analysis
Provide and implement the capability to centrally review and analyze audit records from multiple components within the system.
Official discussion
Automated mechanisms for centralized reviews and analyses include Security Information and Event Management products.
Assessment objectives and methods
- AU-06(04)[01]the capability to centrally review and analyze audit records from multiple components within the system is provided;
- AU-06(04)[02]the capability to centrally review and analyze audit records from multiple components within the system is implemented.
Examine
- Audit and accountability policy
- procedures addressing audit review, analysis, and reporting
- system design documentation
- system configuration settings and associated documentation
- system security plan
- privacy plan
- system audit records
- other relevant documents or records
Interview
- Organizational personnel with audit review, analysis, and reporting responsibilities
- organizational personnel with information security and privacy responsibilities
- system developers
Test
- System capability to centralize review and analysis of audit records
Related controls
AU-6(5) — Integrated Analysis of Audit Records
Integrate analysis of audit records with analysis of [Organization-defined: au-06.05_odp.01] to further enhance the ability to identify inappropriate or unusual activity.
Official discussion
Integrated analysis of audit records does not require vulnerability scanning, the generation of performance data, or system monitoring. Rather, integrated analysis requires that the analysis of information generated by scanning, monitoring, or other data collection activities is integrated with the analysis of audit record information. Security Information and Event Management tools can facilitate audit record aggregation or consolidation from multiple system components as well as audit record correlation and analysis. The use of standardized audit record analysis scripts developed by organizations (with localized script adjustments, as necessary) provides more cost-effective approaches for analyzing audit record information collected. The correlation of audit record information with vulnerability scanning information is important in determining the veracity of vulnerability scans of the system and in correlating attack detection events with scanning results. Correlation with performance data can uncover denial-of-service attacks or other types of attacks that result in the unauthorized use of resources. Correlation with system monitoring information can assist in uncovering attacks and in better relating audit information to operational situations.
Organization-defined parameters (2)
Assessment objectives and methods
analysis of audit records is integrated with analysis of [Organization-defined: au-06.05_odp.01] to further enhance the ability to identify inappropriate or unusual activity.
Examine
- Audit and accountability policy
- system security plan
- privacy plan
- procedures addressing audit review, analysis, and reporting
- system design documentation
- system configuration settings and associated documentation
- integrated analysis of audit records, vulnerability scanning information, performance data, network monitoring information, and associated documentation
- other relevant documents or records
Interview
- Organizational personnel with audit review, analysis, and reporting responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms implementing the capability to integrate analysis of audit records with analysis of data/information sources
Related controls
AU-6(6) — Correlation with Physical Monitoring
Correlate information from audit records with information obtained from monitoring physical access to further enhance the ability to identify suspicious, inappropriate, unusual, or malevolent activity.
Official discussion
The correlation of physical audit record information and the audit records from systems may assist organizations in identifying suspicious behavior or supporting evidence of such behavior. For example, the correlation of an individual’s identity for logical access to certain systems with the additional physical security information that the individual was present at the facility when the logical access occurred may be useful in investigations.
Assessment objectives and methods
information from audit records is correlated with information obtained from monitoring physical access to further enhance the ability to identify suspicious, inappropriate, unusual, or malevolent activity.
Examine
- Audit and accountability policy
- procedures addressing audit review, analysis, and reporting
- procedures addressing physical access monitoring
- system design documentation
- system configuration settings and associated documentation
- documentation providing evidence of correlated information obtained from audit records and physical access monitoring records
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with audit review, analysis, and reporting responsibilities
- organizational personnel with physical access monitoring responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms implementing the capability to correlate information from audit records with information from monitoring physical access
AU-6(7) — Permitted Actions
Specify the permitted actions for each [Organization-defined: au-06.07_odp] associated with the review, analysis, and reporting of audit record information.
Official discussion
Organizations specify permitted actions for system processes, roles, and users associated with the review, analysis, and reporting of audit records through system account management activities. Specifying permitted actions on audit record information is a way to enforce the principle of least privilege. Permitted actions are enforced by the system and include read, write, execute, append, and delete.
Organization-defined parameters (1)
Assessment objectives and methods
the permitted actions for each [Organization-defined: au-06.07_odp] associated with the review, analysis, and reporting of audit record information are specified.
Examine
- Audit and accountability policy
- procedures addressing process, role and/or user permitted actions from audit review, analysis, and reporting
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with audit review, analysis, and reporting responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms supporting permitted actions for the review, analysis, and reporting of audit information
AU-6(8) — Full Text Analysis of Privileged Commands
Perform a full text analysis of logged privileged commands in a physically distinct component or subsystem of the system, or other system that is dedicated to that analysis.
Official discussion
Full text analysis of privileged commands requires a distinct environment for the analysis of audit record information related to privileged users without compromising such information on the system where the users have elevated privileges, including the capability to execute privileged commands. Full text analysis refers to analysis that considers the full text of privileged commands (i.e., commands and parameters) as opposed to analysis that considers only the name of the command. Full text analysis includes the use of pattern matching and heuristics.
Assessment objectives and methods
a full text analysis of logged privileged commands in a physically distinct component or subsystem of the system or other system that is dedicated to that analysis is performed.
Examine
- Audit and accountability policy
- procedures addressing audit review, analysis, and reporting
- system design documentation
- system configuration settings and associated documentation
- text analysis tools and techniques
- text analysis documentation of audited privileged commands
- system security plan
- privacy plan
- other relevant documents or records
Interview
- Organizational personnel with audit review, analysis, and reporting responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms implementing the capability to perform a full text analysis of audited privilege commands
Related controls
AU-6(9) — Correlation with Information from Nontechnical Sources
Correlate information from nontechnical sources with audit record information to enhance organization-wide situational awareness.
Official discussion
Nontechnical sources include records that document organizational policy violations related to harassment incidents and the improper use of information assets. Such information can lead to a directed analytical effort to detect potential malicious insider activity. Organizations limit access to information that is available from nontechnical sources due to its sensitive nature. Limited access minimizes the potential for inadvertent release of privacy-related information to individuals who do not have a need to know. The correlation of information from nontechnical sources with audit record information generally occurs only when individuals are suspected of being involved in an incident. Organizations obtain legal advice prior to initiating such actions.
Assessment objectives and methods
information from non-technical sources is correlated with audit record information to enhance organization-wide situational awareness.
Examine
- Audit and accountability policy
- system security plan
- privacy plan
- procedures addressing audit review, analysis, and reporting
- system design documentation
- system configuration settings and associated documentation
- documentation providing evidence of correlated information obtained from audit records and organization-defined non-technical sources
- list of information types from non-technical sources for correlation with audit information
- other relevant documents or records
Interview
- Organizational personnel with audit review, analysis, and reporting responsibilities
- organizational personnel with information security and privacy responsibilities
Test
- Mechanisms implementing capability to correlate information from non-technical sources
Related controls
AU-6(10) — Audit Level Adjustment
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.