Audit Record Review, Analysis, and Reporting
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of AU-6 — Audit Record Review, Analysis, and Reporting. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of AU-6 — Audit Record Review, Analysis, and Reporting. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of AU-6 — Audit Record Review, Analysis, and Reporting. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
Audit record review, analysis, and reporting covers information security- and privacy-related logging performed by organizations, including logging that results from the monitoring of account usage, remote access, wireless connectivity, mobile device connection, configuration settings, system component inventory, use of maintenance tools and non-local maintenance, physical access, temperature and humidity, equipment delivery and removal, communications at system interfaces, and use of mobile code or Voice over Internet Protocol (VoIP). Findings can be reported to organizational entities that include the incident response team, help desk, and security or privacy offices. If organizations are prohibited from reviewing and analyzing audit records or unable to conduct such activities, the review or analysis may be carried out by other organizations granted such authority. The frequency, scope, and/or depth of the audit record review, analysis, and reporting may be adjusted to meet organizational needs based on new information received.
Enhancements NIST SOURCE
AU-6(1) Automated Process Integration LOW ✓ MODERATE ✓ HIGH
Integrate audit record review, analysis, and reporting processes using [automated mechanisms].
Discussion
Organizational processes that benefit from integrated audit record review, analysis, and reporting include incident response, continuous monitoring, contingency planning, investigation and response to suspicious activities, and Inspector General audits.
AU-6(2) Automated Security Alerts WITHDRAWN
Withdrawn. Incorporated into SI-4.
AU-6(3) Correlate Audit Record Repositories LOW ✓ MODERATE ✓ HIGH
Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.
Discussion
Organization-wide situational awareness includes awareness across all three levels of risk management (i.e., organizational level, mission/business process level, and information system level) and supports cross-organization awareness.
AU-6(4) Central Review and Analysis LOW MODERATE HIGH
Provide and implement the capability to centrally review and analyze audit records from multiple components within the system.
Discussion
Automated mechanisms for centralized reviews and analyses include Security Information and Event Management products.
AU-6(5) Integrated Analysis of Audit Records LOW MODERATE ✓ HIGH
Integrate analysis of audit records with analysis of [one of: vulnerability scanning information; performance data; system monitoring information; ] to further enhance the ability to identify inappropriate or unusual activity.
Discussion
Integrated analysis of audit records does not require vulnerability scanning, the generation of performance data, or system monitoring. Rather, integrated analysis requires that the analysis of information generated by scanning, monitoring, or other data collection activities is integrated with the analysis of audit record information. Security Information and Event Management tools can facilitate audit record aggregation or consolidation from multiple system components as well as audit record correlation and analysis. The use of standardized audit record analysis scripts developed by organizations (with localized script adjustments, as necessary) provides more cost-effective approaches for analyzing audit record information collected. The correlation of audit record information with vulnerability scanning information is important in determining the veracity of vulnerability scans of the system and in correlating attack detection events with scanning results. Correlation with performance data can uncover denial-of-service attacks or other types of attacks that result in the unauthorized use of resources. Correlation with system monitoring information can assist in uncovering attacks and in better relating audit information to operational situations.
AU-6(6) Correlation with Physical Monitoring LOW MODERATE ✓ HIGH
Correlate information from audit records with information obtained from monitoring physical access to further enhance the ability to identify suspicious, inappropriate, unusual, or malevolent activity.
Discussion
The correlation of physical audit record information and the audit records from systems may assist organizations in identifying suspicious behavior or supporting evidence of such behavior. For example, the correlation of an individual’s identity for logical access to certain systems with the additional physical security information that the individual was present at the facility when the logical access occurred may be useful in investigations.
AU-6(7) Permitted Actions LOW MODERATE HIGH
Specify the permitted actions for each [one of: system process; role; user] associated with the review, analysis, and reporting of audit record information.
Discussion
Organizations specify permitted actions for system processes, roles, and users associated with the review, analysis, and reporting of audit records through system account management activities. Specifying permitted actions on audit record information is a way to enforce the principle of least privilege. Permitted actions are enforced by the system and include read, write, execute, append, and delete.
AU-6(8) Full Text Analysis of Privileged Commands LOW MODERATE HIGH
Perform a full text analysis of logged privileged commands in a physically distinct component or subsystem of the system, or other system that is dedicated to that analysis.
Discussion
Full text analysis of privileged commands requires a distinct environment for the analysis of audit record information related to privileged users without compromising such information on the system where the users have elevated privileges, including the capability to execute privileged commands. Full text analysis refers to analysis that considers the full text of privileged commands (i.e., commands and parameters) as opposed to analysis that considers only the name of the command. Full text analysis includes the use of pattern matching and heuristics.
AU-6(9) Correlation with Information from Nontechnical Sources LOW MODERATE HIGH
Correlate information from nontechnical sources with audit record information to enhance organization-wide situational awareness.
Discussion
Nontechnical sources include records that document organizational policy violations related to harassment incidents and the improper use of information assets. Such information can lead to a directed analytical effort to detect potential malicious insider activity. Organizations limit access to information that is available from nontechnical sources due to its sensitive nature. Limited access minimizes the potential for inadvertent release of privacy-related information to individuals who do not have a need to know. The correlation of information from nontechnical sources with audit record information generally occurs only when individuals are suspected of being involved in an incident. Organizations obtain legal advice prior to initiating such actions.
AU-6(10) Audit Level Adjustment WITHDRAWN
Withdrawn. Incorporated into AU-6.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for AU-6 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- frequency at which system audit records are reviewed and analyzed is defined;
- inappropriate or unusual activity is defined;
- personnel or roles to receive findings from reviews and analyses of system records is/are defined;
- system audit records are reviewed and analyzed <AU-06_ODP[01] frequency> for indications of <AU-06_ODP[02] inappropriate or unusual activity> and the potential impact of the inappropriate or unusual activity;
- findings are reported to <AU-06_ODP[03] personnel or roles>;
- the level of audit record review, analysis, and reporting within the system is adjusted when there is a change in risk based on law enforcement information, intelligence information, or other credible sources of information.
Examine
[SELECT FROM: Audit and accountability policy; system security plan; privacy plan; procedures addressing audit review, analysis, and reporting; reports of audit findings; records of actions taken in response to reviews/analyses of audit records; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with audit review, analysis, and reporting responsibilities; organizational personnel with information security and privacy responsibilities].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for AU-6. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Audit and accountability policy
- system security plan
- privacy plan
Other Records
- procedures addressing audit review, analysis, and reporting
- reports of audit findings
- records of actions taken in response to reviews/analyses of audit records
- other relevant documents or records