03.03: Audit and Accountability

Controls

03.03.01: Event Logging

Specify the following event types selected for logging within the system: [Assignment: organization-defined event types]. Review and update the event types selected for logging [Assignment: organization-defined frequency].

03.03.02: Audit Record Content

Include the following content in audit records: What type of event occurred When the event occurred Where the event occurred Source of the event Outcome of the event Identity of the individuals, subjects, objects, or entities associated with the event Provide additional information for audit records as needed.

03.03.03: Audit Record Generation

Generate audit records for the selected event types and audit record content specified in 03.03.01 and 03.03.02. Retain audit records for a time period consistent with the records retention policy.

03.03.04: Response to Audit Logging Process Failures

Alert organizational personnel or roles within [Assignment: organization-defined time period] in the event of an audit logging process failure. Take the following additional actions: [Assignment: organization-defined additional actions].

03.03.05: Audit Record Review, Analysis, and Reporting

Review and analyze system audit records [Assignment: organization-defined frequency] for indications and the potential impact of inappropriate or unusual activity. Report findings to organizational personnel or roles. Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.

03.03.06: Audit Record Reduction and Report Generation

Implement an audit record reduction and report generation capability that supports audit record review, analysis, reporting requirements, and after-the-fact investigations of incidents. Preserve the original content and time ordering of audit records.

03.03.07: Time Stamps

Use internal system clocks to generate time stamps for audit records. Record time stamps for audit records that meet [Assignment: organization-defined granularity of time measurement] and that use Coordinated Universal Time (UTC), have a fixed local time offset from UTC, or include the local time offset as part of the time stamp.

03.03.08: Protection of Audit Information

Protect audit information and audit logging tools from unauthorized access, modification, and deletion. Authorize access to management of audit logging functionality to only a subset of privileged users or roles.