Response to Audit Logging Process Failures

✓ LOW ✓ MODERATE ✓ HIGH
5 Enhancements 1 Overlay 9 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Discussion (NIST Supplemental Guidance)

Audit logging process failures include software and hardware errors, failures in audit log capturing mechanisms, and reaching or exceeding audit log storage capacity. Organization-defined actions include overwriting oldest audit records, shutting down the system, and stopping the generation of audit records. Organizations may choose to define additional actions for audit logging process failures based on the type of failure, the location of the failure, the severity of the failure, or a combination of such factors. When the audit logging process failure is related to storage, the response is carried out for the audit log storage repository (i.e., the distinct system component where the audit logs are stored), the system on which the audit logs reside, the total audit log storage capacity of the organization (i.e., all audit log storage repositories combined), or all three. Organizations may decide to take no additional actions after alerting designated roles or personnel.

Enhancements NIST SOURCE

AU-5(1) Storage Capacity Warning LOW MODERATE ✓ HIGH

Provide a warning to [personnel, roles, and/or locations] within [time period] when allocated audit log storage volume reaches [percentage] of repository maximum audit log storage capacity.

Discussion

Organizations may have multiple audit log storage repositories distributed across multiple system components with each repository having different storage volume capacities.

Open full page for AU-5(1) →
AU-5(2) Real-time Alerts LOW MODERATE ✓ HIGH

Provide an alert within [real-time period] to [personnel, roles, and/or locations] when the following audit failure events occur: [audit logging failure events requiring real-time alerts].

Discussion

Alerts provide organizations with urgent messages. Real-time alerts provide these messages at information technology speed (i.e., the time from event detection to alert occurs in seconds or less).

Open full page for AU-5(2) →
AU-5(3) Configurable Traffic Volume Thresholds LOW MODERATE HIGH

Enforce configurable network communications traffic volume thresholds reflecting limits on audit log storage capacity and [one of: reject; delay] network traffic above those thresholds.

Discussion

Organizations have the capability to reject or delay the processing of network communications traffic if audit logging information about such traffic is determined to exceed the storage capacity of the system audit logging function. The rejection or delay response is triggered by the established organizational traffic volume thresholds that can be adjusted based on changes to audit log storage capacity.

Open full page for AU-5(3) →
AU-5(4) Shutdown on Failure LOW MODERATE HIGH

Invoke a [one of: full system shutdown; partial system shutdown; degraded operational mode with limited mission or business functionality available] in the event of [audit logging failures] , unless an alternate audit logging capability exists.

Discussion

Organizations determine the types of audit logging failures that can trigger automatic system shutdowns or degraded operations. Because of the importance of ensuring mission and business continuity, organizations may determine that the nature of the audit logging failure is not so severe that it warrants a complete shutdown of the system supporting the core organizational mission and business functions. In those instances, partial system shutdowns or operating in a degraded mode with reduced capability may be viable alternatives.

Open full page for AU-5(4) →
AU-5(5) Alternate Audit Logging Capability LOW MODERATE HIGH

Provide an alternate audit logging capability in the event of a failure in primary audit logging capability that implements [alternate audit logging functionality].

Discussion

Since an alternate audit logging capability may be a short-term protection solution employed until the failure in the primary audit logging capability is corrected, organizations may determine that the alternate audit logging capability need only provide a subset of the primary audit logging functionality that is impacted by the failure.

Open full page for AU-5(5) →

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for AU-5 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. personnel or roles receiving audit logging process failure alerts are defined;
  2. time period for personnel or roles receiving audit logging process failure alerts is defined;
  3. additional actions to be taken in the event of an audit logging process failure are defined;
  4. <AU-05_ODP[01] personnel or roles> are alerted in the event of an audit logging process failure within <AU-05_ODP[02] time period>;
  5. <AU-05_ODP[03] additional actions> are taken in the event of an audit logging process failure.

Examine

[SELECT FROM: Audit and accountability policy; procedures addressing response to audit processing failures; system design documentation; system security plan; privacy plan; system configuration settings and associated documentation; list of personnel to be notified in case of an audit processing failure; system audit records; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with audit and accountability responsibilities; organizational personnel with information security and privacy responsibilities; system/network administrators; system developers].

Test

[SELECT FROM: Mechanisms implementing system response to audit processing failures].

Overlays

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

  • Base control: Included (matches standard baseline)

MODERATE

  • Base control: Included (matches standard baseline)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (2)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for AU-5. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Audit and accountability policy
  • system security plan
  • privacy plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Mechanisms implementing system response to audit processing failures

Other Records

  • procedures addressing response to audit processing failures
  • list of personnel to be notified in case of an audit processing failure
  • system audit records
  • other relevant documents or records