Device Class 3: Response To Audit Processing Failures
| Control ID: AU-5 Response To Audit Processing Failures | Family: Audit and Accountability | Source: NIST 800-53r4 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
Control: The information system:
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Supplemental Guidance: Audit processing failures include, for example, software/hardware errors, failures in the audit capturing mechanisms, and audit storage capacity being reached or exceeded. Organizations may choose to define additional actions for different audit processing failures (e.g., by type, by location, by severity, or a combination of such factors). This control applies to each audit data storage repository (i.e., distinct information system component where audit records are stored), the total audit storage capacity of organizations (i.e., all audit data storage repositories combined), or both. Related Controls: AU-4, SI-12 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Control Enhancements:
(1) Response To Audit Processing Failures | Audit Storage Capacity The information system provides a warning to [Assignment: organization-defined personnel, roles, and/or locations] within [Assignment: organization-defined time period] when allocated audit record storage volume reaches [Assignment: organization-defined percentage] of repository maximum audit record storage capacity. Supplemental Guidance: Organizations may have multiple audit data storage repositories distributed across multiple information system components, with each repository having different storage volume capacities. Related Controls: N/A (2) Response To Audit Processing Failures | Real-time Alerts The information system provides an alert in [Assignment: organization-defined real-time period] to [Assignment: organization-defined personnel, roles, and/or locations] when the following audit failure events occur: [Assignment: organization-defined audit failure events requiring real-time alerts]. Supplemental Guidance: Alerts provide organizations with urgent messages. Real-time alerts provide these messages at information technology speed (i.e., the time from event detection to alert occurs in seconds or less). Related Controls: N/A |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| References: N/A | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Mechanisms:
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Protocol Implementation Conformance Statements:
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||