FedRAMP - Audit Generation AU-12


Overview:
The information system:
a. Provides audit record generation capability for the auditable events defined in AU-2 a. at [Assignment: organization-defined information system components];
b. Allows [Assignment: organization-defined personnel or roles] to select which auditable events are to be audited by specific components of the information system; and
c. Generates audit records for the events defined in AU-2 d. with the content defined in AU-3.


Supplemental Guidance:
Audit records can be generated from many different information system components. The list of audited events is the set of events for which audits are to be generated. These events are typically a subset of all events for which the information system is capable of generating audit records.


Related controls: AC-3, AU-2, AU-3, AU-6, AU-7.


Action Items:
1) Ensure that components of systems are capable of auditing events


Related Documents:
1) Audit and Accountability Policy

2) Logging and Monitoring Policy


Additional Guidance:
Moderate FedRAMP-Defined Assignment / Selection Parameters
AU-12 (a) [all information system and network components where audit capability is deployed/available]


Moderate Additional FedRAMP Requirements and Guidance
none



Article ID: 624
Created: September 29, 2022
Last Updated: September 29, 2022
Author: Matthew Burdick

Online URL: http://www.compliancewiki.org/article/fedramp-audit-generation-au-12-624.html