id: "AU-03(03)" title: "Limit Personally Identifiable Information Elements" family: "AU" family_name: "Audit and Accountability" sort_id: "au-03.03" priority: "P2" implementation_level: "organization" parent: "AU-03" enhancement: True
Statement
Limit personally identifiable information contained in audit records to the following elements identified in the privacy risk assessment: {{ insert: param, au-03.03_odp }}.
Guidance
Limiting personally identifiable information in audit records when such information is not needed for operational purposes helps reduce the level of privacy risk created by a system.
Assessment Objective
personally identifiable information contained in audit records is limited to {{ insert: param, au-03.03_odp }} identified in the privacy risk assessment.
Audit and accountability policy
system security plan
privacy plan
privacy risk assessment
privacy risk assessment results
procedures addressing content of audit records
system design documentation
system configuration settings and associated documentation
list of organization-defined auditable events
system audit records
third party contracts
other relevant documents or records
Organizational personnel with audit and accountability responsibilities
organizational personnel with information security and privacy responsibilities
system/network administrators
system developers
system audit capability