AU-16(3): Disassociability

Control Statement

Implement [Assignment: organization-defined measures] to disassociate individuals from audit information transmitted across organizational boundaries.

Supplemental Guidance

Preserving identities in audit trails could have privacy ramifications, such as enabling the tracking and profiling of individuals, but may not be operationally necessary. These risks could be further amplified when transmitting information across organizational boundaries. Implementing privacy-enhancing cryptographic techniques can disassociate individuals from audit information and reduce privacy risk while maintaining accountability.