← AU-6

Integrated Analysis of Audit Records

LOW MODERATE ✓ HIGH
1 Overlay 2 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

Integrate analysis of audit records with analysis of [one of: vulnerability scanning information; performance data; system monitoring information; ] to further enhance the ability to identify inappropriate or unusual activity.

Discussion (NIST Supplemental Guidance)

Integrated analysis of audit records does not require vulnerability scanning, the generation of performance data, or system monitoring. Rather, integrated analysis requires that the analysis of information generated by scanning, monitoring, or other data collection activities is integrated with the analysis of audit record information. Security Information and Event Management tools can facilitate audit record aggregation or consolidation from multiple system components as well as audit record correlation and analysis. The use of standardized audit record analysis scripts developed by organizations (with localized script adjustments, as necessary) provides more cost-effective approaches for analyzing audit record information collected. The correlation of audit record information with vulnerability scanning information is important in determining the veracity of vulnerability scans of the system and in correlating attack detection events with scanning results. Correlation with performance data can uncover denial-of-service attacks or other types of attacks that result in the unauthorized use of resources. Correlation with system monitoring information can assist in uncovering attacks and in better relating audit information to operational situations.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for AU-6(5) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

NIST SP 800-53A REV 5.2.0

Assessment Objectives

  1. one or more of the following PARAMETER VALUES is/are selected: {vulnerability scanning information; performance data; system monitoring information; <AU-06(05)_ODP[02] data/information collected from other sources>};
  2. data/information collected from other sources to be analyzed is defined (if selected);
  3. analysis of audit records is integrated with analysis of <AU-06(05)_ODP[01] SELECTED PARAMETER VALUES> to further enhance the ability to identify inappropriate or unusual activity.

Examine

[SELECT FROM: Audit and accountability policy; system security plan; privacy plan; procedures addressing audit review, analysis, and reporting; system design documentation; system configuration settings and associated documentation; integrated analysis of audit records, vulnerability scanning information, performance data, network monitoring information, and associated documentation; other relevant documents or records].

Interview

[SELECT FROM: Organizational personnel with audit review, analysis, and reporting responsibilities; organizational personnel with information security and privacy responsibilities].

Test

[SELECT FROM: Mechanisms implementing the capability to integrate analysis of audit records with analysis of data/information sources].

Overlays

Showing the OT/ICS overlay for the parent control AU-6 — see the AU-6(5) entries within each baseline below.

OT/ICS Overlay SP 800-82r3

NIST SP 800-82r3 Appendix F, Table 22. Blank baseline means the control/control enhancement is not selected in that initial OT baseline.

LOW

Excluded — not selected in the OT baseline at this tier, though the standard SP 800-53 baseline includes the base control.

MODERATE

  • Base control: Included (matches standard baseline)
  • Included: (1) (3)

HIGH

  • Base control: Included (matches standard baseline)
  • Included: (1) (3) (5) (6)

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for AU-6(5). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

Potential Evidence — Derived

Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.

Policy

  • Audit and accountability policy
  • system security plan
  • privacy plan

Configuration

  • system design documentation
  • system configuration settings and associated documentation

Testing

  • Mechanisms implementing the capability to integrate analysis of audit records with analysis of data/information sources

Other Records

  • procedures addressing audit review, analysis, and reporting
  • integrated analysis of audit records, vulnerability scanning information, performance data, network monitoring information, and associated documentation
  • other relevant documents or records