id: "AU-09(02)" title: "Store on Separate Physical Systems or Components" family: "AU" family_name: "Audit and Accountability" sort_id: "au-09.02" priority: "P2" implementation_level: "system" parent: "AU-09" enhancement: True
Statement
Store audit records {{ insert: param, au-09.02_odp }} in a repository that is part of a physically different system or system component than the system or component being audited.
Guidance
Storing audit records in a repository separate from the audited system or system component helps to ensure that a compromise of the system being audited does not also result in a compromise of the audit records. Storing audit records on separate physical systems or components also preserves the confidentiality and integrity of audit records and facilitates the management of audit records as an organization-wide activity. Storing audit records on separate systems or components applies to initial generation as well as backup or long-term storage of audit records.
Assessment Objective
audit records are stored {{ insert: param, au-09.02_odp }} in a repository that is part of a physically different system or system component than the system or component being audited.
Audit and accountability policy
system security plan
privacy plan
procedures addressing protection of audit information
system design documentation
system configuration settings and associated documentation
system or media storing backups of system audit records
system audit records
other relevant documents or records
Organizational personnel with audit and accountability responsibilities
organizational personnel with information security and privacy responsibilities
system/network administrators
system developers
Mechanisms implementing the backing up of audit records