id: "AU-09(06)" title: "Read-only Access" family: "AU" family_name: "Audit and Accountability" sort_id: "au-09.06" priority: "P2" implementation_level: "system" parent: "AU-09" enhancement: True


Statement

Authorize read-only access to audit information to {{ insert: param, au-09.06_odp }}.

Guidance

Restricting privileged user or role authorizations to read-only helps to limit the potential damage to organizations that could be initiated by such users or roles, such as deleting audit records to cover up malicious activity.

Assessment Objective

read-only access to audit information is authorized to {{ insert: param, au-09.06_odp }}.

Audit and accountability policy

system security plan

privacy plan

access control policy and procedures

procedures addressing protection of audit information

system design documentation

system configuration settings and associated documentation

system-generated list of privileged users with read-only access to audit information

access authorizations

access control list

system audit records

other relevant documents or records

Organizational personnel with audit and accountability responsibilities

organizational personnel with information security and privacy responsibilities

system/network administrators

Mechanisms managing access to audit information