id: "AU-12" title: "Audit Record Generation" family: "AU" family_name: "Audit and Accountability" sort_id: "au-12" priority: "P2" implementation_level: "system" enhancements: - au-12.1 - au-12.2 - au-12.3 - au-12.4


Provide audit record generation capability for the event types the system is capable of auditing as defined in AU-2a on {{ insert: param, au-12_odp.01 }};

Allow {{ insert: param, au-12_odp.02 }} to select the event types that are to be logged by specific components of the system; and

Generate audit records for the event types defined in AU-2c that include the audit record content defined in AU-3.

Guidance

Audit records can be generated from many different system components. The event types specified in AU-2d are the event types for which audit logs are to be generated and are a subset of all event types for which the system can generate audit records.

Assessment Objective: audit record generation capability for the event types the system is capable of auditing (defined in AU-02_ODP[01]) is provided by {{ insert: param, au-12_odp.01 }};

Assessment Objective: {{ insert: param, au-12_odp.02 }} is/are allowed to select the event types that are to be logged by specific components of the system;

Assessment Objective: audit records for the event types defined in AU-02_ODP[02] that include the audit record content defined in AU-03 are generated.

Audit and accountability policy

procedures addressing audit record generation

system security plan

privacy plan

system design documentation

system configuration settings and associated documentation

list of auditable events

system audit records

other relevant documents or records

Organizational personnel with audit record generation responsibilities

organizational personnel with information security and privacy responsibilities

system/network administrators

system developers

Mechanisms implementing audit record generation capability