AU: Audit and Accountability

OT Tailoring Considerations

In general, security audit information and audit tools are not available on legacy OT. When OT cannot support the specific audit and accountability requirements of a control, the organization employs compensating controls in accordance with the general tailoring guidance. For example, organizations may want to consider whether security audit information is available from separate systems or system components (e.g., the historian, firewall logs, physical security systems). Additional examples of compensating controls are given with each control as appropriate.

Controls

AU-1: Policy and Procedures

Baseline(s):

  • Low
  • Moderate
  • High
  • Privacy
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Develop, document, and disseminate to [Assignment: organization-defined personnel or roles]: [Assignment (one or more): organization-level, mission/business process-level, system-level] audit and accountability policy that: Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and Is consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines; and Procedures to facilitate the…

AU-2: Event Logging

Baseline(s):

  • Low
  • Moderate
  • High
  • Privacy
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Identify the types of events that the system is capable of logging in support of the audit function: [Assignment: organization-defined event types]; Coordinate the event logging function with other organizational entities requiring audit-related information to guide and inform the selection criteria for events to be logged; Specify the following event types for logging within the…

AU-3: Content of Audit Records

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Ensure that audit records contain information that establishes the following: What type of event occurred; When the event occurred; Where the event occurred; Source of the event; Outcome of the event; and Identity of any individuals, subjects, or objects/entities associated with the event.

AU-4: Audit Log Storage Capacity

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Allocate audit log storage capacity to accommodate [Assignment: organization-defined audit log retention requirements].

AU-5: Response to Audit Logging Process Failures

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Alert [Assignment: organization-defined personnel or roles] within [Assignment: organization-defined time period] in the event of an audit logging process failure; and Take the following additional actions: [Assignment: organization-defined additional actions].

AU-6: Audit Record Review, Analysis, and Reporting

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Review and analyze system audit records [Assignment: organization-defined frequency] for indications of [Assignment: organization-defined inappropriate or unusual activity] and the potential impact of the inappropriate or unusual activity; Report findings to [Assignment: organization-defined personnel or roles] ; and Adjust the level of audit record review, analysis, and reporting within the system when there is a…

AU-7: Audit Record Reduction and Report Generation

Baseline(s):

  • Moderate
  • High
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Provide and implement an audit record reduction and report generation capability that: Supports on-demand audit record review, analysis, and reporting requirements and after-the-fact investigations of incidents; and Does not alter the original content or time ordering of audit records.

AU-8: Time Stamps

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Use internal system clocks to generate time stamps for audit records; and Record time stamps for audit records that meet [Assignment: organization-defined granularity of time measurement] and that use Coordinated Universal Time, have a fixed local time offset from Coordinated Universal Time, or that include the local time offset as part of the time stamp.

AU-9: Protection of Audit Information

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Protect audit information and audit logging tools from unauthorized access, modification, and deletion; and Alert [Assignment: organization-defined personnel or roles] upon detection of unauthorized access, modification, or deletion of audit information.

AU-10: Non-repudiation

Baseline(s):

  • High
  • OT High (SP 800-82r3)

Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [Assignment: organization-defined actions].

AU-11: Audit Record Retention

Baseline(s):

  • Low
  • Moderate
  • High
  • Privacy
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Retain audit records for [Assignment: organization-defined time period] to provide support for after-the-fact investigations of incidents and to meet regulatory and organizational information retention requirements.

AU-12: Audit Record Generation

Baseline(s):

  • Low
  • Moderate
  • High
  • OT Low (SP 800-82r3)
  • OT Moderate (SP 800-82r3)
  • OT High (SP 800-82r3)

Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on [Assignment: organization-defined system components]; Allow [Assignment: organization-defined personnel or roles] to select the event types that are to be logged by specific components of the system; and Generate audit records for the event types defined…

AU-13: Monitoring for Information Disclosure

Baseline(s):

(Not part of any baseline)

Monitor [Assignment: organization-defined open-source information and/or information sites] [Assignment: organization-defined frequency] for evidence of unauthorized disclosure of organizational information; and If an information disclosure is discovered: Notify [Assignment: organization-defined personnel or roles] ; and Take the following additional actions: [Assignment: organization-defined additional actions].

AU-14: Session Audit

Baseline(s):

(Not part of any baseline)

Provide and implement the capability for [Assignment: organization-defined users or roles] to [Assignment (one or more): record, view, hear, log] the content of a user session under [Assignment: organization-defined circumstances] ; and Develop, integrate, and use session auditing activities in consultation with legal counsel and in accordance with applicable laws, executive orders, directives, regulations, policies,…

AU-16: Cross-organizational Audit Logging

Baseline(s):

(Not part of any baseline)

Employ [Assignment: organization-defined methods] for coordinating [Assignment: organization-defined audit information] among external organizations when audit information is transmitted across organizational boundaries.