id: "AU-03(03)" title: "Limit Personally Identifiable Information Elements" family: "AU" family_name: "Audit and Accountability" sort_id: "au-03.03" priority: "P2" implementation_level: "organization" parent: "AU-03" enhancement: True


Statement

Limit personally identifiable information contained in audit records to the following elements identified in the privacy risk assessment: {{ insert: param, au-03.03_odp }}.

Guidance

Limiting personally identifiable information in audit records when such information is not needed for operational purposes helps reduce the level of privacy risk created by a system.

Assessment Objective

personally identifiable information contained in audit records is limited to {{ insert: param, au-03.03_odp }} identified in the privacy risk assessment.

Audit and accountability policy

system security plan

privacy plan

privacy risk assessment

privacy risk assessment results

procedures addressing content of audit records

system design documentation

system configuration settings and associated documentation

list of organization-defined auditable events

system audit records

third party contracts

other relevant documents or records

Organizational personnel with audit and accountability responsibilities

organizational personnel with information security and privacy responsibilities

system/network administrators

system developers

system audit capability