Non-repudiation

LOW MODERATE ✓ HIGH
4 Enhancements 1 Overlay 9 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [actions].

Discussion (NIST Supplemental Guidance)

Types of individual actions covered by non-repudiation include creating information, sending and receiving messages, and approving information. Non-repudiation protects against claims by authors of not having authored certain documents, senders of not having transmitted messages, receivers of not having received messages, and signatories of not having signed documents. Non-repudiation services can be used to determine if information originated from an individual or if an individual took specific actions (e.g., sending an email, signing a contract, approving a procurement request, or receiving specific information). Organizations obtain non-repudiation services by employing various techniques or mechanisms, including digital signatures and digital message receipts.

Enhancements NIST SOURCE

AU-10(1) Association of Identities LOW MODERATE HIGH
  1. (a) Bind the identity of the information producer with the information to [strength of binding] ; and
  2. (b) Provide the means for authorized individuals to determine the identity of the producer of the information.
Discussion

Binding identities to the information supports audit requirements that provide organizational personnel with the means to identify who produced specific information in the event of an information transfer. Organizations determine and approve the strength of attribute binding between the information producer and the information based on the security category of the information and other relevant risk factors.

Open full page for AU-10(1) →
AU-10(2) Validate Binding of Information Producer Identity LOW MODERATE HIGH
  1. (a) Validate the binding of the information producer identity to the information at [frequency] ; and
  2. (b) Perform [actions] in the event of a validation error.
Discussion

Validating the binding of the information producer identity to the information prevents the modification of information between production and review. The validation of bindings can be achieved by, for example, using cryptographic checksums. Organizations determine if validations are in response to user requests or generated automatically.

Open full page for AU-10(2) →
AU-10(3) Chain of Custody LOW MODERATE HIGH

Maintain reviewer or releaser credentials within the established chain of custody for information reviewed or released.

Discussion

Chain of custody is a process that tracks the movement of evidence through its collection, safeguarding, and analysis life cycle by documenting each individual who handled the evidence, the date and time the evidence was collected or transferred, and the purpose for the transfer. If the reviewer is a human or if the review function is automated but separate from the release or transfer function, the system associates the identity of the reviewer of the information to be released with the information and the information label. In the case of human reviews, maintaining the credentials of reviewers or releasers provides the organization with the means to identify who reviewed and released the information. In the case of automated reviews, it ensures that only approved review functions are used.

Open full page for AU-10(3) →
AU-10(4) Validate Binding of Information Reviewer Identity LOW MODERATE HIGH
  1. (a) Validate the binding of the information reviewer identity to the information at the transfer or release points prior to release or transfer between [security domains] ; and
  2. (b) Perform [actions] in the event of a validation error.
Discussion

Validating the binding of the information reviewer identity to the information at transfer or release points prevents the unauthorized modification of information between review and the transfer or release. The validation of bindings can be achieved by using cryptographic checksums. Organizations determine if validations are in response to user requests or generated automatically.

Open full page for AU-10(4) →
AU-10(5) Digital Signatures WITHDRAWN

Withdrawn. Incorporated into SI-7.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for AU-10 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. actions to be covered by non-repudiation are defined;
  2. irrefutable evidence is provided that an individual (or process acting on behalf of an individual) has performed <AU-10_ODP actions>.

Examine

[SELECT FROM: Audit and accountability policy; system security plan; privacy plan; procedures addressing non-repudiation; system design documentation; system configuration settings and associated documentation; system audit records; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with information security and privacy responsibilities; system/network administrators; system developers].

Test

[SELECT FROM: Mechanisms implementing non-repudiation capability].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

Not applicable at this tier.

MODERATE

Not applicable at this tier.

HIGH

  • Base control: Included (matches standard baseline)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for AU-10. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Audit and accountability policy
  • system security plan
  • privacy plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Mechanisms implementing non-repudiation capability

Other Records

  • procedures addressing non-repudiation
  • system audit records
  • other relevant documents or records