id: "AU-05(01)" title: "Storage Capacity Warning" family: "AU" family_name: "Audit and Accountability" sort_id: "au-05.01" priority: "P2" implementation_level: "system" parent: "AU-05" enhancement: True


Statement

Provide a warning to {{ insert: param, au-05.01_odp.01 }} within {{ insert: param, au-05.01_odp.02 }} when allocated audit log storage volume reaches {{ insert: param, au-05.01_odp.03 }} of repository maximum audit log storage capacity.

Guidance

Organizations may have multiple audit log storage repositories distributed across multiple system components with each repository having different storage volume capacities.

Assessment Objective

a warning is provided to {{ insert: param, au-05.01_odp.01 }} within {{ insert: param, au-05.01_odp.02 }} when allocated audit log storage volume reaches {{ insert: param, au-05.01_odp.03 }} of repository maximum audit log storage capacity.

Audit and accountability policy

procedures addressing response to audit processing failures

system design documentation

system security plan

privacy system configuration settings and associated documentation

system audit records

other relevant documents or records

Organizational personnel with audit and accountability responsibilities

organizational personnel with information security and privacy responsibilities

system/network administrators

system developers

Mechanisms implementing audit storage limit warnings