id: "AU-09(04)" title: "Access by Subset of Privileged Users" family: "AU" family_name: "Audit and Accountability" sort_id: "au-09.04" priority: "P2" implementation_level: "organization" parent: "AU-09" enhancement: True
Statement
Authorize access to management of audit logging functionality to only {{ insert: param, au-09.04_odp }}.
Guidance
Individuals or roles with privileged access to a system and who are also the subject of an audit by that system may affect the reliability of the audit information by inhibiting audit activities or modifying audit records. Requiring privileged access to be further defined between audit-related privileges and other privileges limits the number of users or roles with audit-related privileges.
Assessment Objective
access to management of audit logging functionality is authorized only to {{ insert: param, au-09.04_odp }}.
Audit and accountability policy
system security plan
privacy plan
access control policy and procedures
procedures addressing protection of audit information
system design documentation
system configuration settings and associated documentation
system-generated list of privileged users with access to management of audit functionality
access authorizations
access control list
system audit records
other relevant documents or records
Organizational personnel with audit and accountability responsibilities
organizational personnel with information security and privacy responsibilities
system/network administrators
Mechanisms managing access to audit functionality