Integrated Analysis of Audit Records
LOW MODERATE ✓ HIGHRequirements NIST SOURCE
Integrate analysis of audit records with analysis of [one of: vulnerability scanning information; performance data; system monitoring information; ] to further enhance the ability to identify inappropriate or unusual activity.
Discussion (NIST Supplemental Guidance)
Integrated analysis of audit records does not require vulnerability scanning, the generation of performance data, or system monitoring. Rather, integrated analysis requires that the analysis of information generated by scanning, monitoring, or other data collection activities is integrated with the analysis of audit record information. Security Information and Event Management tools can facilitate audit record aggregation or consolidation from multiple system components as well as audit record correlation and analysis. The use of standardized audit record analysis scripts developed by organizations (with localized script adjustments, as necessary) provides more cost-effective approaches for analyzing audit record information collected. The correlation of audit record information with vulnerability scanning information is important in determining the veracity of vulnerability scans of the system and in correlating attack detection events with scanning results. Correlation with performance data can uncover denial-of-service attacks or other types of attacks that result in the unauthorized use of resources. Correlation with system monitoring information can assist in uncovering attacks and in better relating audit information to operational situations.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for AU-6(5) yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- one or more of the following PARAMETER VALUES is/are selected: {vulnerability scanning information; performance data; system monitoring information; <AU-06(05)_ODP[02] data/information collected from other sources>};
- data/information collected from other sources to be analyzed is defined (if selected);
- analysis of audit records is integrated with analysis of <AU-06(05)_ODP[01] SELECTED PARAMETER VALUES> to further enhance the ability to identify inappropriate or unusual activity.
Examine
[SELECT FROM: Audit and accountability policy; system security plan; privacy plan; procedures addressing audit review, analysis, and reporting; system design documentation; system configuration settings and associated documentation; integrated analysis of audit records, vulnerability scanning information, performance data, network monitoring information, and associated documentation; other relevant documents or records].
Interview
[SELECT FROM: Organizational personnel with audit review, analysis, and reporting responsibilities; organizational personnel with information security and privacy responsibilities].
Test
[SELECT FROM: Mechanisms implementing the capability to integrate analysis of audit records with analysis of data/information sources].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for AU-6(5). This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- Audit and accountability policy
- system security plan
- privacy plan
Configuration
- system design documentation
- system configuration settings and associated documentation
Testing
- Mechanisms implementing the capability to integrate analysis of audit records with analysis of data/information sources
Other Records
- procedures addressing audit review, analysis, and reporting
- integrated analysis of audit records, vulnerability scanning information, performance data, network monitoring information, and associated documentation
- other relevant documents or records