FedRAMP Controls / AU

AU-3 Content of Audit Records

Family AU
Baselines moderate
Mapped KSIs 2

Control statement

Ensure that audit records contain information that establishes the following:
    a. What type of event occurred;
    b. When the event occurred;
    c. Where the event occurred;
    d. Source of the event;
    e. Outcome of the event; and
    f. Identity of any individuals, subjects, or objects/entities associated with the event.

Parameter placeholders {{ insert: param, … }} reference FedRAMP-set values in the resolved profile. Full parameter map is preserved in the catalog database.

Covered by these Key Security Indicators

KSITitleCategory
KSI-AFR-03Authorization Data Sharing
Determine how authorization data will be shared with all necessary parties in alignment with the FedRAMP Authorization Data Sharing (ADS) process and persistently address all related requirements and recommendations.
Authorization by FedRAMP
KSI-MLA-01Security Information and Event Management (SIEM)
Operate a Security Information and Event Management (SIEM) or similar system(s) for centralized, tamper-resistent logging of events, activities, and changes.
Monitoring, Logging, and Auditing