Response to Audit Logging Process Failures
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of AU-5 — Response to Audit Logging Process Failures. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of AU-5 — Response to Audit Logging Process Failures. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Audit logging process failures include software and hardware errors, failures in audit log capturing mechanisms, and reaching or exceeding audit log storage capacity. Organization-defined actions include overwriting oldest audit records, shutting down the system, and stopping the generation of audit records. Organizations may choose to define additional actions for audit logging process failures based on the type of failure, the location of the failure, the severity of the failure, or a combination of such factors. When the audit logging process failure is related to storage, the response is carried out for the audit log storage repository (i.e., the distinct system component where the audit logs are stored), the system on which the audit logs reside, the total audit log storage capacity of the organization (i.e., all audit log storage repositories combined), or all three. Organizations may decide to take no additional actions after alerting designated roles or personnel.
Enhancements NIST SOURCE
AU-5(1) Storage Capacity Warning LOW MODERATE ✓ HIGH
Provide a warning to [personnel, roles, and/or locations] within [time period] when allocated audit log storage volume reaches [percentage] of repository maximum audit log storage capacity.
Discussion
Organizations may have multiple audit log storage repositories distributed across multiple system components with each repository having different storage volume capacities.
AU-5(2) Real-time Alerts LOW MODERATE ✓ HIGH
Provide an alert within [real-time period] to [personnel, roles, and/or locations] when the following audit failure events occur: [audit logging failure events requiring real-time alerts].
Discussion
Alerts provide organizations with urgent messages. Real-time alerts provide these messages at information technology speed (i.e., the time from event detection to alert occurs in seconds or less).
AU-5(3) Configurable Traffic Volume Thresholds LOW MODERATE HIGH
Enforce configurable network communications traffic volume thresholds reflecting limits on audit log storage capacity and [one of: reject; delay] network traffic above those thresholds.
Discussion
Organizations have the capability to reject or delay the processing of network communications traffic if audit logging information about such traffic is determined to exceed the storage capacity of the system audit logging function. The rejection or delay response is triggered by the established organizational traffic volume thresholds that can be adjusted based on changes to audit log storage capacity.
AU-5(4) Shutdown on Failure LOW MODERATE HIGH
Invoke a [one of: full system shutdown; partial system shutdown; degraded operational mode with limited mission or business functionality available] in the event of [audit logging failures] , unless an alternate audit logging capability exists.
Discussion
Organizations determine the types of audit logging failures that can trigger automatic system shutdowns or degraded operations. Because of the importance of ensuring mission and business continuity, organizations may determine that the nature of the audit logging failure is not so severe that it warrants a complete shutdown of the system supporting the core organizational mission and business functions. In those instances, partial system shutdowns or operating in a degraded mode with reduced capability may be viable alternatives.
AU-5(5) Alternate Audit Logging Capability LOW MODERATE HIGH
Provide an alternate audit logging capability in the event of a failure in primary audit logging capability that implements [alternate audit logging functionality].
Discussion
Since an alternate audit logging capability may be a short-term protection solution employed until the failure in the primary audit logging capability is corrected, organizations may determine that the alternate audit logging capability need only provide a subset of the primary audit logging functionality that is impacted by the failure.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for AU-5 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- personnel or roles receiving audit logging process failure alerts are defined;
- time period for personnel or roles receiving audit logging process failure alerts is defined;
- additional actions to be taken in the event of an audit logging process failure are defined;
- <AU-05_ODP[01] personnel or roles> are alerted in the event of an audit logging process failure within <AU-05_ODP[02] time period>;
- <AU-05_ODP[03] additional actions> are taken in the event of an audit logging process failure.
Examine
[SELECT FROM: Audit and accountability policy; procedures addressing response to audit processing failures; system design documentation; system security plan; privacy plan; system configuration settings and associated documentation; list of personnel to be notified in case of an audit processing failure; system audit records; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with audit and accountability responsibilities; organizational personnel with information security and privacy responsibilities; system/network administrators; system developers].
Test
[SELECT FROM: Mechanisms implementing system response to audit processing failures].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for AU-5. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Audit and accountability policy
- system security plan
- privacy plan
Configuration
- system design documentation
- system configuration settings and associated documentation
Testing
- Mechanisms implementing system response to audit processing failures
Other Records
- procedures addressing response to audit processing failures
- list of personnel to be notified in case of an audit processing failure
- system audit records
- other relevant documents or records