<?xml version="1.0"?>

<rss version="2.0">


<channel>
<title>Home - All Categories - FedRAMP  - Audit and Accountability &amp;#40;AU&amp;#41;  </title>
<link>http://www.compliancewiki.org/category/fedramp/audit-and-accountability-au/10/</link>
<description>This RSS Feed contains Articles of Category in the knowledge base. You can click on the title to view its content. Powered by PHPKB (https://www.phpkb.com)</description>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-audit-record-retention-au-11-623.html</guid>
										<title>FedRAMP - Audit Record Retention AU-11</title>
										<link>http://www.compliancewiki.org/article/fedramp-audit-record-retention-au-11-623.html</link>
										<description><![CDATA[Overview:The organization retains audit records for [Assignment: organization-defined time period consistent with records retention policy] to provide support for after-the-fact investigations of security incidents and to meet regulatory and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-synchronization-with-authoritative-time-source-au-8-1-619.html</guid>
										<title>FedRAMP - Synchronization with Authoritative Time Source AU-8&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-synchronization-with-authoritative-time-source-au-8-1-619.html</link>
										<description><![CDATA[Overview:The information system:(a) Compares the internal information system clocks [Assignment: organization-defined frequency] with [Assignment: organization-defined authoritative time source]; and(b) Synchronizes the internal system clocks to the...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-audit-events-au-2-607.html</guid>
										<title>FedRAMP - Audit Events AU-2</title>
										<link>http://www.compliancewiki.org/article/fedramp-audit-events-au-2-607.html</link>
										<description><![CDATA[Overview:The organization:a. Determines that the information system is capable of auditing the following events: [Assignment: organization-defined auditable events];b. Coordinates the security audit function with other organizational entities...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-audit-and-accountability-policy-and-procedures-au-1-606.html</guid>
										<title>FedRAMP - Audit and Accountability Policy and Procedures AU-1</title>
										<link>http://www.compliancewiki.org/article/fedramp-audit-and-accountability-policy-and-procedures-au-1-606.html</link>
										<description><![CDATA[Overview:The organization:a. Develops, documents, and disseminates to [Assignment: organization-defined personnel or roles]:1. An audit and accountability policy that addresses purpose, scope, roles, responsibilities, management commitment,...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-audit-backup-on-separate-physical-systems-and-components-au-9-2-621.html</guid>
										<title>FedRAMP - Audit Backup on Separate Physical Systems and Components AU-9&#40;2&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-audit-backup-on-separate-physical-systems-and-components-au-9-2-621.html</link>
										<description><![CDATA[Overview:The information system backs up audit records [Assignment: organization-defined frequency] onto a physically different system or system component than the system or component being audited. Supplemental Guidance:This control enhancement...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-audit-generation-au-12-624.html</guid>
										<title>FedRAMP - Audit Generation AU-12</title>
										<link>http://www.compliancewiki.org/article/fedramp-audit-generation-au-12-624.html</link>
										<description><![CDATA[Overview:The information system:a. Provides audit record generation capability for the auditable events defined in AU-2 a. at [Assignment: organization-defined information system components];b. Allows [Assignment: organization-defined personnel or...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-additional-audit-information-au-3-1-610.html</guid>
										<title>FedRAMP - Additional Audit Information AU-3&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-additional-audit-information-au-3-1-610.html</link>
										<description><![CDATA[Overview:The information system generates audit records containing the following additional information: [Assignment: organization-defined additional, more detailed information]. Supplemental Guidance:Detailed information that organizations may...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-response-to-audit-processing-failures-au-5-612.html</guid>
										<title>FedRAMP - Response to Audit Processing Failures AU-5</title>
										<link>http://www.compliancewiki.org/article/fedramp-response-to-audit-processing-failures-au-5-612.html</link>
										<description><![CDATA[Overview:The information system:a. Alerts [Assignment: organization-defined personnel or roles] in the event of an audit processing failure; andb. Takes the following additional actions: [Assignment: organization-defined actions to be taken (e.g.,...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-audit-review-analysis-and-reporting-au-6-613.html</guid>
										<title>FedRAMP - Audit Review, Analysis, and Reporting AU-6</title>
										<link>http://www.compliancewiki.org/article/fedramp-audit-review-analysis-and-reporting-au-6-613.html</link>
										<description><![CDATA[Overview:The organization:a. Reviews and analyzes information system audit records [Assignment: organization-defined frequency] for indications of [Assignment: organization-defined inappropriate or unusual activity]; andb. Reports findings to ...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-audit-reduction-and-report-generation-au-7-616.html</guid>
										<title>FedRAMP - Audit Reduction and Report Generation AU-7</title>
										<link>http://www.compliancewiki.org/article/fedramp-audit-reduction-and-report-generation-au-7-616.html</link>
										<description><![CDATA[Overview:The information system provides an audit reduction and report generation capability that:a. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents; andb. Does not alter...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-access-by-subset-of-privileged-user-au-9-4-622.html</guid>
										<title>FedRAMP - Access by Subset of Privileged User AU-9&#40;4&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-access-by-subset-of-privileged-user-au-9-4-622.html</link>
										<description><![CDATA[Overview:The organization authorizes access to management of audit functionality to only [Assignment: organization-defined subset of privileged users]. Supplemental Guidance:Individuals with privileged access to an information system and who are also...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-audit-storage-capacity-au-4-611.html</guid>
										<title>FedRAMP - Audit Storage Capacity AU-4</title>
										<link>http://www.compliancewiki.org/article/fedramp-audit-storage-capacity-au-4-611.html</link>
										<description><![CDATA[Overview:The organization allocates audit record storage capacity in accordance with [Assignment:organization-defined audit record storage requirements]. Supplemental Guidance:Organizations consider the types of auditing to be performed and the audit...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-content-of-audit-records-au-3-609.html</guid>
										<title>FedRAMP - Content of Audit Records AU-3</title>
										<link>http://www.compliancewiki.org/article/fedramp-content-of-audit-records-au-3-609.html</link>
										<description><![CDATA[Overview:The information system generates audit records containing information that establishes what type of event occurred, when the event occurred, where the event occurred, the source of the event, the outcome of the event, and the identity of any...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-reviews-and-updates-au-2-3-608.html</guid>
										<title>FedRAMP - Reviews and Updates AU-2&#40;3&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-reviews-and-updates-au-2-3-608.html</link>
										<description><![CDATA[Overview:The organization reviews and updates the audited events [Assignment: organization-defined frequency]. Supplemental Guidance:Over time, the events that organizations believe should be audited may change. Reviewing and updating the set of...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-automatic-processing-au-7-1-617.html</guid>
										<title>FedRAMP - Automatic Processing AU-7&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-automatic-processing-au-7-1-617.html</link>
										<description><![CDATA[Overview:The information system provides the capability to process audit records for events of interest based on [Assignment: organization-defined audit fields within audit records]. Supplemental Guidance:Events of interest can be identified by the...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-correlate-audit-repositories-au-6-3-615.html</guid>
										<title>FedRAMP - Correlate Audit Repositories AU-6&#40;3&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-correlate-audit-repositories-au-6-3-615.html</link>
										<description><![CDATA[Overview:The organization analyzes and correlates audit records across different repositories to gain organization-wide situational awareness. Supplemental Guidance:Organization-wide situational awareness includes awareness across all three tiers of...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-process-integration-au-6-1-614.html</guid>
										<title>FedRAMP - Process Integration AU-6&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/fedramp-process-integration-au-6-1-614.html</link>
										<description><![CDATA[Overview:The organization employs automated mechanisms to integrate audit review, analysis, and reporting processes to support organizational processes for investigation and response to suspicious activities. Supplemental Guidance:Organizational...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-protection-of-audit-information-au-9-620.html</guid>
										<title>FedRAMP - Protection of Audit Information AU-9</title>
										<link>http://www.compliancewiki.org/article/fedramp-protection-of-audit-information-au-9-620.html</link>
										<description><![CDATA[Overview:The information system protects audit information and audit tools from unauthorized access, modification, and deletion. Supplemental Guidance:Audit information includes all information (e.g., audit records, audit settings, and audit reports)...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/fedramp-time-stamps-au-8-618.html</guid>
										<title>FedRAMP - Time Stamps AU-8</title>
										<link>http://www.compliancewiki.org/article/fedramp-time-stamps-au-8-618.html</link>
										<description><![CDATA[Overview:The information system:a. Uses internal system clocks to generate time stamps for audit records; andb. Records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT) and meets ...]]></description>

									</item>

</channel>

</rss>