id: "AU-05(03)" title: "Configurable Traffic Volume Thresholds" family: "AU" family_name: "Audit and Accountability" sort_id: "au-05.03" priority: "P2" implementation_level: "system" parent: "AU-05" enhancement: True


Statement

Enforce configurable network communications traffic volume thresholds reflecting limits on audit log storage capacity and {{ insert: param, au-05.03_odp }} network traffic above those thresholds.

Guidance

Organizations have the capability to reject or delay the processing of network communications traffic if audit logging information about such traffic is determined to exceed the storage capacity of the system audit logging function. The rejection or delay response is triggered by the established organizational traffic volume thresholds that can be adjusted based on changes to audit log storage capacity.

Assessment Objective: configurable network communications traffic volume thresholds reflecting limits on audit log storage capacity are enforced;

Assessment Objective: network traffic is {{ insert: param, au-05.03_odp }} if network traffic volume is above configured thresholds.

Audit and accountability policy

procedures addressing response to audit processing failures

system design documentation

system security plan

privacy plan

system configuration settings and associated documentation

system audit records

other relevant documents or records

Organizational personnel with audit and accountability responsibilities

organizational personnel with information security and privacy responsibilities

system/network administrators

system developers