Skip to Content

FedRAMP - Audit Reduction and Report Generation AU-7

Overview:
The information system provides an audit reduction and report generation capability that:
a. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; and
b. Does not alter the original content or time ordering of audit records.


Supplemental Guidance:
Audit reduction is a process that manipulates collected audit information and organizes such information in a summary format that is more meaningful to analysts. Audit reduction and report generation capabilities do not always emanate from the same information system or from the same organizational entities conducting auditing activities. Audit reduction capability can include, for example, modern data mining techniques with advanced data filters to identify anomalous behavior in audit records. The report generation capability provided by the information system can generate customizable reports. Time ordering of audit records can be a significant issue if the granularity of the timestamp in the record is insufficient.


Related control: AU-6.


Action Items:
1) Ensure information systems have the capability to provide audit reduction and report generation capabilities to assist the analyst in analyzation

2) Ensure the reduction and reporting does not modify the original time or content


Related Documents:
1) Audit and Accountability Policy

2) Logging and Monitoring Policy

 


Additional Guidance:
Moderate FedRAMP-Defined Assignment / Selection Parameters
none


Moderate Additional FedRAMP Requirements and Guidance
none