NIST Special Publication 800-53 Revision 5.2.0
IDNameBaselinesThreats
LowModerateHighPrivacyOT Low (SP 800-82r3)OT Moderate (SP 800-82r3)OT High (SP 800-82r3)
AC-2(4)Automated Audit Actions ••  ••STRIDE-LM
(9)Restrictions on Use of Shared and Group Accounts       STRIDE-LM
AC-3(10)Audited Override of Access Control Mechanisms       STRIDE-LM
AC-4(26)Audit Filtering Actions       STRIDE-LM
AC-6(9)Log Use of Privileged Functions ••  ••STRIDE-LM
AU-2Event Logging•••••••STRIDE-LM
AU-3Content of Audit Records••• •••STRIDE-LM
(1)Additional Audit Information ••  ••STRIDE-LM
AU-5Response to Audit Logging Process Failures••• •••STRIDE-LM
(5)Alternate Audit Logging Capability       STRIDE-LM
AU-6Audit Record Review, Analysis, and Reporting••• •••STRIDE-LM
(1)Automated Process Integration ••  ••STRIDE-LM
(3)Correlate Audit Record Repositories ••  ••STRIDE-LM
(7)Permitted Actions       STRIDE-LM
AU-7(1)Automatic Processing ••  ••STRIDE-LM
AU-8Time Stamps••• •••STRIDE-LM
AU-9Protection of Audit Information••• •••STRIDE-LM
AU-10Non-repudiation  •   •STRIDE-LM
(1)Association of Identities       STRIDE-LM
(2)Validate Binding of Information Producer Identity       STRIDE-LM
(3)Chain of Custody       STRIDE-LM
(4)Validate Binding of Information Reviewer Identity       STRIDE-LM
AU-11Audit Record Retention•••••••STRIDE-LM
(1)Long-term Retrieval Capability       STRIDE-LM
AU-12Audit Record Generation••• •••STRIDE-LM
(1)System-wide and Time-correlated Audit Trail  •   •STRIDE-LM
(2)Standardized Formats       STRIDE-LM
(4)Query Parameter Audits of Personally Identifiable Information       STRIDE-LM
AU-14Session Audit       STRIDE-LM
AU-16Cross-organizational Audit Logging       STRIDE-LM
(1)Identity Preservation       STRIDE-LM
(2)Sharing of Audit Information       STRIDE-LM
CM-5(1)Automated Access Enforcement and Audit Records  •   •STRIDE-LM
CM-8(4)Accountability Information  •   •STRIDE-LM
MA-4(1)Logging and Review     ••STRIDE-LM
PE-5(2)Link to Individual Identity       STRIDE-LM
PE-8(1)Automated Records Maintenance and Review  •   •STRIDE-LM
PM-21Accounting of Disclosures   •   STRIDE-LM
RA-5(8)Review Historic Audit Logs       STRIDE-LM
SA-8(22)Accountability and Traceability       STRIDE-LM
SA-15(13)Logging Syntax       STRIDE-LM
SC-7(8)Route Traffic to Authenticated Proxy Servers ••  ••STRIDE-LM
SC-11(1)Irrefutable Communications Path       STRIDE-LM
SC-12(3)Asymmetric Keys       STRIDE-LM
SC-45System Time Synchronization    •••STRIDE-LM
(1)Synchronization with Authoritative Time Source       STRIDE-LM
SI-4(16)Correlate Monitoring Information       STRIDE-LM
SI-7(8)Auditing Capability for Significant Events       STRIDE-LM