id: "AU-09" title: "Protection of Audit Information" family: "AU" family_name: "Audit and Accountability" sort_id: "au-09" priority: "P2" implementation_level: "system" enhancements: - au-9.1 - au-9.2 - au-9.3 - au-9.4 - au-9.5 - au-9.6 - au-9.7


Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and

Alert {{ insert: param, au-09_odp }} upon detection of unauthorized access, modification, or deletion of audit information.

Guidance

Audit information includes all information needed to successfully audit system activity, such as audit records, audit log settings, audit reports, and personally identifiable information. Audit logging tools are those programs and devices used to conduct system audit and logging activities. Protection of audit information focuses on technical protection and limits the ability to access and execute audit logging tools to authorized individuals. Physical protection of audit information is addressed by both media protection controls and physical and environmental protection controls.

Assessment Objective: audit information and audit logging tools are protected from unauthorized access, modification, and deletion;

Assessment Objective: {{ insert: param, au-09_odp }} are alerted upon detection of unauthorized access, modification, or deletion of audit information.

Audit and accountability policy

system security plan

privacy plan

access control policy and procedures

procedures addressing protection of audit information

system design documentation

system configuration settings and associated documentation

system audit records

audit tools

other relevant documents or records

Organizational personnel with audit and accountability responsibilities

organizational personnel with information security and privacy responsibilities

system/network administrators

system developers

Mechanisms implementing audit information protection