id: "AU-06(07)" title: "Permitted Actions" family: "AU" family_name: "Audit and Accountability" sort_id: "au-06.07" priority: "P2" implementation_level: "organization" parent: "AU-06" enhancement: True


Statement

Specify the permitted actions for each {{ insert: param, au-06.07_odp }} associated with the review, analysis, and reporting of audit record information.

Guidance

Organizations specify permitted actions for system processes, roles, and users associated with the review, analysis, and reporting of audit records through system account management activities. Specifying permitted actions on audit record information is a way to enforce the principle of least privilege. Permitted actions are enforced by the system and include read, write, execute, append, and delete.

Assessment Objective

the permitted actions for each {{ insert: param, au-06.07_odp }} associated with the review, analysis, and reporting of audit record information are specified.

Audit and accountability policy

procedures addressing process, role and/or user permitted actions from audit review, analysis, and reporting

system security plan

privacy plan

other relevant documents or records

Organizational personnel with audit review, analysis, and reporting responsibilities

organizational personnel with information security and privacy responsibilities

Mechanisms supporting permitted actions for the review, analysis, and reporting of audit information