FedRAMP Controls / AU

AU-12 Audit Record Generation

Family AU
Baselines moderate
Mapped KSIs 1

Control statement

a. Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on {{ insert: param, au-12_odp.01 }};
    b. Allow {{ insert: param, au-12_odp.02 }} to select the event types that are to be logged by specific components of the system; and
    c. Generate audit records for the event types defined in [AU-2c](#au-2_smt.c) that include the audit record content defined in [AU-3](#au-3).

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-MLA-07Event Types
Maintain a list of information resources and event types that will be monitored, logged, and audited, then do so.
Monitoring, Logging, and Auditing