id: "AU-09" title: "Protection of Audit Information" family: "AU" family_name: "Audit and Accountability" sort_id: "au-09" priority: "P2" implementation_level: "system" enhancements: - au-9.1 - au-9.2 - au-9.3 - au-9.4 - au-9.5 - au-9.6 - au-9.7
Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and
Alert {{ insert: param, au-09_odp }} upon detection of unauthorized access, modification, or deletion of audit information.
Guidance
Audit information includes all information needed to successfully audit system activity, such as audit records, audit log settings, audit reports, and personally identifiable information. Audit logging tools are those programs and devices used to conduct system audit and logging activities. Protection of audit information focuses on technical protection and limits the ability to access and execute audit logging tools to authorized individuals. Physical protection of audit information is addressed by both media protection controls and physical and environmental protection controls.
Assessment Objective: audit information and audit logging tools are protected from unauthorized access, modification, and deletion;
Assessment Objective: {{ insert: param, au-09_odp }} are alerted upon detection of unauthorized access, modification, or deletion of audit information.
Audit and accountability policy
system security plan
privacy plan
access control policy and procedures
procedures addressing protection of audit information
system design documentation
system configuration settings and associated documentation
system audit records
audit tools
other relevant documents or records
Organizational personnel with audit and accountability responsibilities
organizational personnel with information security and privacy responsibilities
system/network administrators
system developers
Mechanisms implementing audit information protection