id: "AU-09(04)" title: "Access by Subset of Privileged Users" family: "AU" family_name: "Audit and Accountability" sort_id: "au-09.04" priority: "P2" implementation_level: "organization" parent: "AU-09" enhancement: True


Statement

Authorize access to management of audit logging functionality to only {{ insert: param, au-09.04_odp }}.

Guidance

Individuals or roles with privileged access to a system and who are also the subject of an audit by that system may affect the reliability of the audit information by inhibiting audit activities or modifying audit records. Requiring privileged access to be further defined between audit-related privileges and other privileges limits the number of users or roles with audit-related privileges.

Assessment Objective

access to management of audit logging functionality is authorized only to {{ insert: param, au-09.04_odp }}.

Audit and accountability policy

system security plan

privacy plan

access control policy and procedures

procedures addressing protection of audit information

system design documentation

system configuration settings and associated documentation

system-generated list of privileged users with access to management of audit functionality

access authorizations

access control list

system audit records

other relevant documents or records

Organizational personnel with audit and accountability responsibilities

organizational personnel with information security and privacy responsibilities

system/network administrators

Mechanisms managing access to audit functionality